Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

github: Replace dependabot with internal tooling #166

Merged
merged 1 commit into from
Nov 7, 2023

Conversation

radeksimko
Copy link
Member

This disables dependabot for GHA to avoid conflicts with our own internal tooling, which comes with an added layer of trusted/reviewed revisions.

@radeksimko radeksimko added the dependencies Auto-pinning label Nov 7, 2023
@radeksimko radeksimko requested a review from kmoe November 7, 2023 15:36
Copy link
Contributor

@bflad bflad left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me 🚀 If you're using any hashicorp/* actions, please note that they have some awkward (non-)handling currently. There's an issue in the TSCCR repository about that.

@radeksimko radeksimko merged commit 1626fa4 into main Nov 7, 2023
@radeksimko radeksimko deleted the gh-disable-gha-dependabot branch November 7, 2023 16:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Auto-pinning
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants