Skip to content

Conversation

mfranzke
Copy link
Member

@mfranzke mfranzke commented Jun 2, 2023

As we use this dependency only within our GitHub Action but not within any JavaScript, it's easy not to pin it to a minor or even patch version, but only major.

https://github.com/trufflesecurity/trufflehog#octocat-trufflehog-github-action even includes trufflesecurity/trufflehog@main to not even pin the major version, but that sounds a little bit too much to me at the moment. (This approach doesn't work, but only releases and main)

As we use this dependency only within our GitHub Action but not within any JavaScript, it's easy not to pin it to a minor or even patch version, but only major.
@mfranzke mfranzke added improvement dependencies Pull requests that update a dependency file labels Jun 2, 2023
@mfranzke mfranzke added this to the Release 2.x milestone Jun 2, 2023
@mfranzke mfranzke requested a review from nmerget as a code owner June 2, 2023 14:45
@mfranzke mfranzke self-assigned this Jun 2, 2023
@mfranzke mfranzke requested review from annsch and dkolba as code owners June 2, 2023 14:45
@github-actions github-actions bot added the cicd label Jun 2, 2023
@github-actions
Copy link
Contributor

github-actions bot commented Jun 2, 2023

🔭🐙🐈 Test this branch here: https://db-ui.github.io/core/review/mfranzke-patch-2

@mfranzke mfranzke marked this pull request as draft June 2, 2023 15:04
@mfranzke mfranzke marked this pull request as ready for review June 2, 2023 15:18
@mfranzke mfranzke enabled auto-merge (squash) June 2, 2023 15:18
@mfranzke mfranzke merged commit ca466d5 into main Jun 5, 2023
@mfranzke mfranzke deleted the mfranzke-patch-2 branch June 5, 2023 13:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cicd dependencies Pull requests that update a dependency file improvement

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants