Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update CodeQL actions to v2 and enable Dependabot for GitHub Actions #72

Merged
merged 1 commit into from
Jul 19, 2023

Conversation

cspicer
Copy link
Contributor

@cspicer cspicer commented Feb 13, 2023

This PR enables Dependabot to manage GitHub Action versions by automatically opening a new PR when an update is available. Dependabot is being enabled specifically to manage the version of CodeQL Actions as GitHub has officially deprecated the code scanning CodeQL Action v1 starting in January 2023.

These Actions need to be updated to avoid interruptions to builds. Once this PR is merged the only further required action will be to review and merge PRs generated by Dependabot for GitHub Actions as they come up.

If you have any questions please let me know!

Thank you!

@cspicer cspicer requested a review from a team as a code owner February 13, 2023 08:57
@cspicer cspicer changed the title SECU-10072 Update CodeQL actions to v2 and enable Dependabot for GitHub Actions Update CodeQL actions to v2 and enable Dependabot for GitHub Actions Feb 25, 2023
Copy link
Collaborator

@kietdo360 kietdo360 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@cspicer cspicer merged commit 512e5ec into master Jul 19, 2023
1 check passed
@cspicer cspicer deleted the secu-10072-codeql-dependabot-update branch July 19, 2023 00:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants