Skip to content

github: Replace dependabot with internal tooling#166

Merged
radeksimko merged 1 commit intomainfrom
gh-disable-gha-dependabot
Nov 7, 2023
Merged

github: Replace dependabot with internal tooling#166
radeksimko merged 1 commit intomainfrom
gh-disable-gha-dependabot

Conversation

@radeksimko
Copy link
Copy Markdown
Member

This disables dependabot for GHA to avoid conflicts with our own internal tooling, which comes with an added layer of trusted/reviewed revisions.

@radeksimko radeksimko added the dependencies Auto-pinning label Nov 7, 2023
@radeksimko radeksimko requested a review from kmoe November 7, 2023 15:36
Copy link
Copy Markdown
Contributor

@bflad bflad left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me 🚀 If you're using any hashicorp/* actions, please note that they have some awkward (non-)handling currently. There's an issue in the TSCCR repository about that.

@radeksimko radeksimko merged commit 1626fa4 into main Nov 7, 2023
@radeksimko radeksimko deleted the gh-disable-gha-dependabot branch November 7, 2023 16:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Auto-pinning

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants