Skip to content

Do not use Dependabot to update Github Actions#525

Merged
martin-g merged 2 commits intomainfrom
asf-infra-morons
Mar 30, 2026
Merged

Do not use Dependabot to update Github Actions#525
martin-g merged 2 commits intomainfrom
asf-infra-morons

Conversation

@martin-g
Copy link
Copy Markdown
Member

@martin-g martin-g commented Mar 30, 2026

This does not work well anymore.
ASF Infra team uses a whitelist of allowed plugins + their versions and they always lack behind.
We will have to update the actions manually from now on after consulting with https://github.com/apache/infrastructure-actions/blob/main/actions.yml.

This does not work well anymore.
ASF Infra team uses a whitelist of allowed plugins and their versions
and they always lack behind
Copilot AI review requested due to automatic review settings March 30, 2026 11:40
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Removes Dependabot configuration for GitHub Actions updates to align with ASF Infra’s whitelisted GitHub Actions/plugin version policy.

Changes:

  • Deleted the github-actions package-ecosystem entry from Dependabot configuration so it no longer opens update PRs for workflow action versions.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@martin-g
Copy link
Copy Markdown
Member Author

#526 should be merged first

@martin-g martin-g added this to the 0.22.0 milestone Mar 30, 2026
@martin-g martin-g merged commit e27e5ea into main Mar 30, 2026
13 checks passed
@martin-g martin-g deleted the asf-infra-morons branch March 30, 2026 17:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants