Skip to content

Conversation

v1v
Copy link
Member

@v1v v1v commented Mar 26, 2025

What does this pull request do?

Use dependabot for updating docker images stored in our internal docker registry using this.

Use directories to manage the dependencies for the GitHub workflow sand composite actions.

Why

We already have secrets stored for accessing the internal docker registry. Use one dependency management tool with native support for GitHub actions and the GH secrets access control.

This has been already tested in the past in a sandbox repository and also in another GH internal repositories.

Actions

  • Create Dependabot GitHub secret using CasC.

Related issues

See elastic/apm-agent-python#2246

@v1v v1v requested review from a team March 26, 2025 11:55
@v1v v1v self-assigned this Mar 26, 2025
@v1v v1v merged commit df03fbf into elastic:main Mar 27, 2025
12 checks passed
This was referenced Mar 27, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants