Commit dbc9671
committed
ci: clean up Dependabot config and apply pending action bumps
Bring the post-v0.1.0 Dependabot work into one commit:
* Remove duplicate `/.github/workflows` ecosystem entry — the
github-actions ecosystem at `/` already recursively scans
`.github/workflows/`, so the second entry was producing two
PRs per action.
* Add `groups.actions-minor` so future Monday-morning runs roll
minor and patch bumps into one grouped PR. Majors still arrive
as individual PRs because they're more likely to need review.
* Apply the four pending major bumps left outstanding when
v0.1.0 shipped (all four target tags verified to exist):
actions/checkout v5 -> v6
actions/upload-artifact v4 -> v7
softprops/action-gh-release v2 -> v3
azure/trusted-signing-action v0.5.1 -> v2
The original Dependabot PRs got closed when v0.1.0 was
force-pushed and their head branches deleted; Dependabot
refuses to re-propose under its already-closed dedup rule,
so applying them directly was the only path forward.
trusted-signing-action@v2 isn't exercised by CI until the
AZURE_TRUSTED_SIGNING_* repo secrets are configured. The pin is
current; behavior only changes once signing is wired up.1 parent 2ffd174 commit dbc9671
3 files changed
Lines changed: 18 additions & 24 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
4 | | - | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
5 | 7 | | |
6 | 8 | | |
7 | 9 | | |
| |||
16 | 18 | | |
17 | 19 | | |
18 | 20 | | |
19 | | - | |
20 | | - | |
21 | | - | |
22 | | - | |
23 | | - | |
24 | | - | |
25 | | - | |
26 | | - | |
27 | | - | |
28 | | - | |
29 | | - | |
30 | | - | |
31 | | - | |
32 | | - | |
33 | | - | |
34 | | - | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
25 | | - | |
| 25 | + | |
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
| |||
82 | 82 | | |
83 | 83 | | |
84 | 84 | | |
85 | | - | |
| 85 | + | |
86 | 86 | | |
87 | 87 | | |
88 | 88 | | |
89 | 89 | | |
90 | 90 | | |
91 | 91 | | |
92 | | - | |
| 92 | + | |
93 | 93 | | |
94 | 94 | | |
95 | 95 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
50 | 50 | | |
51 | 51 | | |
52 | 52 | | |
53 | | - | |
| 53 | + | |
54 | 54 | | |
55 | 55 | | |
56 | 56 | | |
| |||
132 | 132 | | |
133 | 133 | | |
134 | 134 | | |
135 | | - | |
| 135 | + | |
136 | 136 | | |
137 | 137 | | |
138 | 138 | | |
| |||
190 | 190 | | |
191 | 191 | | |
192 | 192 | | |
193 | | - | |
| 193 | + | |
194 | 194 | | |
195 | 195 | | |
196 | 196 | | |
197 | 197 | | |
198 | 198 | | |
199 | 199 | | |
200 | 200 | | |
201 | | - | |
| 201 | + | |
202 | 202 | | |
203 | 203 | | |
204 | 204 | | |
| |||
0 commit comments