Enable GH Actions to be automatically bumped

Turns out those get new major releases somewhat often, and we get deprecation warnings and brownouts and all that.
Automatic bumps should help us avoid that, though I've set a *very* large scan interval to shield us from churn.
This commit is contained in:
Eldred Habert
2026-03-31 02:03:37 +02:00
committed by GitHub
parent efd4373a56
commit 5090395ca7
+14
View File
@@ -0,0 +1,14 @@
# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file
version: 2
updates:
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "quarterly" # We do not need *immediate* bumps, only frequent enough to avoid falling out of support range.
cooldown: # Avoid bumping deps immediately, to give time for security audits to be conducted
default-days: 15
include: [ * ]
groups:
actions:
labels: [ builds ] # Since those are CI-related updates...