Commit d5ff757
committed
docs: address PR review feedback on bot-guard rationale and Dependabot workflow PRs
- pr-review.md: clarify that dependabot[bot] is skipped because dependency-pr-review
owns automated review for dependency bumps (RI-1).
- CONTRIBUTING.md: document that Dependabot PRs bumping action SHAs inside
.github/workflows/*.yml require manual maintainer review because GitHub strips
secrets from workflow-file PRs (RI-3).1 parent 7605608 commit d5ff757
2 files changed
Lines changed: 10 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
67 | 67 | | |
68 | 68 | | |
69 | 69 | | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
70 | 73 | | |
71 | 74 | | |
72 | 75 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
91 | 91 | | |
92 | 92 | | |
93 | 93 | | |
| 94 | + | |
94 | 95 | | |
95 | 96 | | |
96 | 97 | | |
| |||
242 | 243 | | |
243 | 244 | | |
244 | 245 | | |
| 246 | + | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
245 | 252 | | |
246 | 253 | | |
247 | 254 | | |
| |||
0 commit comments