Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Set up Dependabot to update GitHub Actions #981

Merged
merged 1 commit into from
Jan 24, 2024

Conversation

fingolfin
Copy link
Contributor

@fingolfin fingolfin commented Jan 24, 2024

I've noticed warnings at e.g. https://github.com/semigroups/Semigroups/actions/runs/7628515256 node12 versus nod16 etc. etc. due to the use of the outdated codecov/codecov-action@v2. Using Dependabot helps avoid this by ensuring GH Actions are always used in their most up-to-date version.

@james-d-mitchell
Copy link
Collaborator

Thanks, I also tried to add this for Digraphs I think but simply adding the file didn't seem to enable anything (certainly no PR's have been opened by dependabot), do I have to enable something else too?

@james-d-mitchell james-d-mitchell added the ci A label for issues or PRs related to the continuous integration for Semigroups label Jan 24, 2024
@fingolfin
Copy link
Contributor Author

I don't recall doing anything special for GAP, but perhaps something needs to be enabled in https://github.com/semigroups/Semigroups/settings/security_analysis ?

@fingolfin
Copy link
Contributor Author

Also nothing will happen before this PR is merged

@james-d-mitchell james-d-mitchell merged commit 2679eac into semigroups:main Jan 24, 2024
13 checks passed
@james-d-mitchell
Copy link
Collaborator

Thanks @fingolfin, I can't see anything to turn at the link you mention. Hopefully this'll just work!

@james-d-mitchell
Copy link
Collaborator

james-d-mitchell commented Jan 24, 2024

Seems to have worked, I wonder if the difference is that this PR targets main and I merged the dependabot file into stable-1.6 of Digraphs.

@fingolfin
Copy link
Contributor Author

Ah, quite likely

@fingolfin fingolfin deleted the mh/dependabot branch January 24, 2024 12:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ci A label for issues or PRs related to the continuous integration for Semigroups
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants