Skip to content

Trust dependabot prs#3771

Merged
patflynn merged 3 commits intomasterfrom
trust-dependabot-prs
Apr 4, 2025
Merged

Trust dependabot prs#3771
patflynn merged 3 commits intomasterfrom
trust-dependabot-prs

Conversation

@patflynn
Copy link
Copy Markdown
Contributor

@patflynn patflynn commented Apr 4, 2025

cargo culting from https://github.com/GoogleCloudPlatform/anthos-samples/pull/573/files. I haven't seen any examples that use dependabot as Google repos seem to prefer renovatebot. I found https://github.com/googleapis/repo-automation-bots/tree/main/packages/trusted-contribution which suggests the GitHub username should work.

patflynn added 2 commits April 4, 2025 11:51
…b-run for it

Signed-off-by: Patrick Flynn <paflynn@google.com>
@patflynn patflynn requested a review from a team as a code owner April 4, 2025 15:56
@patflynn patflynn requested a review from phbnf April 4, 2025 15:56
Co-authored-by: Roger Ng <rogerng@google.com>
@roger2hk
Copy link
Copy Markdown
Contributor

roger2hk commented Apr 4, 2025

I think this will work after installing this GitHub App in this repo.

https://github.com/apps/trusted-contributions-gcf

@patflynn
Copy link
Copy Markdown
Contributor Author

patflynn commented Apr 4, 2025

@roger2hk my suspicion/hope is that this is installed org-wide. I guess we can merge and see if we need to install it? Or is there a way to check?

@roger2hk
Copy link
Copy Markdown
Contributor

roger2hk commented Apr 4, 2025

@roger2hk my suspicion/hope is that this is installed org-wide. I guess we can merge and see if we need to install it? Or is there a way to check?

The "Trusted Contributions GCF" GitHub App is not installed in our repo.

https://github.com/google/trillian/settings/installations

@roger2hk
Copy link
Copy Markdown
Contributor

roger2hk commented Apr 4, 2025

@roger2hk my suspicion/hope is that this is installed org-wide. I guess we can merge and see if we need to install it? Or is there a way to check?

The "Trusted Contributions GCF" GitHub App is not installed in our repo.

https://github.com/google/trillian/settings/installations

You can click "Install & Request" and get someone from OSPO to approve it.

@patflynn patflynn merged commit 69f0435 into master Apr 4, 2025
14 checks passed
@patflynn patflynn deleted the trust-dependabot-prs branch April 4, 2025 19:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants