Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(develop): Included githubactions in the dependabot config, and port Dependabot updates #2307

Merged

Conversation

krashish8
Copy link
Member

naveensrinivasan and others added 4 commits May 25, 2022 15:37
This should help with keeping the GitHub actions updated on new releases. This will also help with keeping it secure.

Dependabot helps in keeping the supply chain secure https://docs.github.com/en/code-security/dependabot

GitHub actions up to date https://docs.github.com/en/code-security/dependabot/working-with-dependabot/keeping-your-actions-up-to-date-with-dependabot

https://github.com/ossf/scorecard/blob/main/docs/checks.md#dependency-update-tool
Signed-off-by: naveen <172697+naveensrinivasan@users.noreply.github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 2 to 3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v2...v3)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [MarkusJx/install-boost](https://github.com/MarkusJx/install-boost) from 1.0.1 to 2.3.0.
- [Release notes](https://github.com/MarkusJx/install-boost/releases)
- [Commits](MarkusJx/install-boost@v1.0.1...v2.3.0)

---
updated-dependencies:
- dependency-name: MarkusJx/install-boost
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 2 to 3.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@v2...v3)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@krashish8 krashish8 added CI Conitnuous Integration dependencies Pull requests that update a dependency file labels May 25, 2022
@krashish8 krashish8 added this to the Release 3.4.0 milestone May 25, 2022
@krashish8 krashish8 requested a review from cvvergara May 25, 2022 13:35
@krashish8 krashish8 merged commit 362be1b into pgRouting:develop May 25, 2022
@krashish8 krashish8 deleted the dependabot-github-actions-develop branch May 25, 2022 14:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
CI Conitnuous Integration dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants