Skip to content

Commit dac21e0

Browse files
authored
Add missing dependabot ignore rules for unapproved GitHub Actions (#110)
* Add missing dependabot ignore rules for unapproved GitHub Actions * Update ignore thresholds to allow approved action versions * Fix upload-artifact threshold: v6.0.0 is approved (PRODSEC-126892)
1 parent cee4f18 commit dac21e0

File tree

1 file changed

+5
-3
lines changed

1 file changed

+5
-3
lines changed

.github/dependabot.yml

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -22,10 +22,12 @@ updates:
2222
timezone: "UTC"
2323
ignore:
2424
- dependency-name: "actions/checkout"
25-
versions: [">=6.0.2"]
25+
versions: [">=6.0.3"]
2626
- dependency-name: "actions/setup-node"
27-
versions: [">=6.2.0"]
27+
versions: [">=6.3.0"]
2828
- dependency-name: "actions/setup-python"
29-
versions: [">=6.1.0"]
29+
versions: [">=6.3.0"]
3030
- dependency-name: "peter-evans/create-pull-request"
3131
versions: [">=8.0.0"]
32+
- dependency-name: "actions/upload-artifact"
33+
versions: [">=7.0.0"]

0 commit comments

Comments
 (0)