Commit f6b1b48
committed
ci(renovate): Use security best practices
- Add config:best-practices to extends (pins digests, GitHub Action digests, config migration, dev dep pinning, abandonment alerts, npm min release age)
- Enable dependencyDashboard (currently false, required by best practices)
- Add minimumReleaseAge: "14 days" to the automerge rule — prevents merging malicious packages before registries can pull them
- Enable osvVulnerabilityAlerts and vulnerabilityAlerts1 parent 4d3e013 commit f6b1b48
1 file changed
Lines changed: 7 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| |||
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
| 24 | + | |
24 | 25 | | |
25 | 26 | | |
26 | 27 | | |
| |||
45 | 46 | | |
46 | 47 | | |
47 | 48 | | |
48 | | - | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
49 | 54 | | |
50 | 55 | | |
51 | 56 | | |
| |||
0 commit comments