-
Notifications
You must be signed in to change notification settings - Fork 0
Add Dependabot or Renovate for automated dependency updates #24
Copy link
Copy link
Open
Labels
ci/cdContinuous integration and deploymentContinuous integration and deploymentsecuritySecurity policies and auditingSecurity policies and auditing
Description
Description
Dependencies should be kept up to date to receive security patches and bug fixes. Automated dependency update tools create PRs when new versions are available.
Proposed Changes
- Add
.github/dependabot.ymlwith:cargopackage ecosystem updates (weekly)github-actionsecosystem updates (weekly)
- Alternatively, configure Renovate with a
renovate.json
Impact
Automated security patches and dependency freshness.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
ci/cdContinuous integration and deploymentContinuous integration and deploymentsecuritySecurity policies and auditingSecurity policies and auditing