Commit Graph
5 Commits
Author SHA1 Message Date
Roger BarretoandGitHub 01a3c5be8a ci: pin third-party GitHub Actions to commit SHAs (#5972)
Replaces every floating tag in our workflow and composite action files
with an immutable 40-character commit SHA, keeping the original `# vX`
comment so Dependabot can still propose version bumps. 186 occurrences
across 25 workflows and 2 composite actions.

Also widens the github-actions Dependabot entry to use the plural
`directories` key with `/.github/actions/*` so composite actions under
`.github/actions/<name>/action.yml` are kept up to date. Previously
Dependabot only scanned `.github/workflows` and the repo-root
`action.yml`, leaving our `python-setup` and `sample-validation-setup`
composite actions unmaintained.
2026-05-20 22:10:32 +00:00
Eduard van ValkenburgandGitHub 57ca139f8c update to dependabot config for python and removed no longer supported experimental (#2269) 2025-11-17 10:29:28 +00:00
Eduard van ValkenburgandGitHub ba9a1a61e1 enable uv ecosystem for dependabot (#751) 2025-09-15 18:16:26 +00:00
Mark WallaceandGitHub c30d726914 Disable some experimental features for dependabot (#170) 2025-07-15 14:08:32 +00:00
Mark WallaceandGitHub 4cafe1c985 Add CodeQL and Dependabot (#159)
* Add CodeQL and Dependabot

* Address code review feedback
2025-07-11 10:34:06 +00:00