Skip to content

Enable Dependabot for Go modules and GitHub Actions#72

Open
alicefr wants to merge 1 commit into
bootc-dev:mainfrom
alicefr:dependabot
Open

Enable Dependabot for Go modules and GitHub Actions#72
alicefr wants to merge 1 commit into
bootc-dev:mainfrom
alicefr:dependabot

Conversation

@alicefr

@alicefr alicefr commented Jun 25, 2026

Copy link
Copy Markdown
Collaborator

Keep dependencies up to date with weekly automated PRs. Updates are grouped by ecosystem (k8s, containers) to reduce PR noise.

Keep dependencies up to date with weekly automated PRs.
Updates are grouped by ecosystem (k8s, containers) to reduce
PR noise.

Assisted-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Signed-off-by: Alice Frosi <afrosi@redhat.com>
Comment thread .github/dependabot.yml

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Might be worth starting from https://github.com/bootc-dev/bootc-operator/blob/main/.github/dependabot.yml instead and adding your groups. The cooldown I think is important.

Should also consider turning on Zizmor, which would warn about this: https://github.com/jlebon/bootc-operator/pull/42

@cgwalters

Copy link
Copy Markdown

In this org we have renovate set up, see bootc-dev/infra#213 which should ensure that these repos get onboarded next run

@cgwalters

Copy link
Copy Markdown

The zizmor thing would also make sense to run globally

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants