Skip to content

ci: add Dependabot config#3

Merged
peo-machine merged 1 commit intomainfrom
dependabot-config
Apr 23, 2026
Merged

ci: add Dependabot config#3
peo-machine merged 1 commit intomainfrom
dependabot-config

Conversation

@peo-machine
Copy link
Copy Markdown
Collaborator

Weekly Dependabot updates for pip (runtime + dev dependencies from pyproject.toml) and github-actions (workflow action versions). Matches the config shipped in 3ncr/tokencrypt#9, 3ncr/nodencrypt#14, and 3ncr/tokencrypt-php#10.

Part of PLAN.md §5d.

peo-machine added a commit that referenced this pull request Apr 23, 2026
Pin actions/checkout and actions/setup-python to their commit SHAs
instead of floating tags, matching the pattern adopted in tokencrypt
PR #10 and nodencrypt PR #16. A mutable tag can be force-pushed to a
malicious commit; a 40-char SHA cannot.

Dependabot's GHA version-update is configured in PR #3 and will keep
these SHAs fresh.

Co-authored-by: peo-machine <peo-machine@users.noreply.github.com>
@peo-machine peo-machine merged commit 3d7d4ab into main Apr 23, 2026
6 checks passed
@peo-machine peo-machine deleted the dependabot-config branch April 23, 2026 03:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant