-
Notifications
You must be signed in to change notification settings - Fork 2.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Use dependabot to manage github action versions in generated projects #41248
Conversation
Status for workflow
|
So +1 but it's weird CI didn't fail as I would have expected some codestarts to fail? Or maybe this file is not included in the files we test? |
I just did a search in
(which is probably fine, IMO, otherwise we'd just be writing things down in two places and the overwhelming cause of test failures would be intentional changes.) |
It's a bit tedious for quarkiverse extension owners to deal with warnings about deprecated versions of github actions and manually update them in my quarkiverse project. Since we generate a workflow file as part of the template, and also a dependabot file, I don't see a downside to having dependabot manage the actions versions.
What do others think?