Skip to content

Configure dependabot to check for new GitHub action versions daily#16

Merged
antonagestam merged 1 commit intoless-action:mainfrom
flaeppe:fix/dependabot
Dec 13, 2023
Merged

Configure dependabot to check for new GitHub action versions daily#16
antonagestam merged 1 commit intoless-action:mainfrom
flaeppe:fix/dependabot

Conversation

@flaeppe
Copy link
Copy Markdown
Contributor

@flaeppe flaeppe commented Dec 13, 2023

Saw a couple of outdated versions. Thought that dependabot might be able to help out keeping things up to date.

Copy link
Copy Markdown
Collaborator

@antonagestam antonagestam left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Super timely, I was thinking just the other day it was probably time to bump some of these.

Btw, I've been meaning to switch to the "trusted publisher" workflow for PyPI. Do you think that would make sense for 5M?

@antonagestam antonagestam merged commit f8a6cfe into less-action:main Dec 13, 2023
@flaeppe
Copy link
Copy Markdown
Contributor Author

flaeppe commented Dec 13, 2023

Haha, I see.

While I'll not pretend that I'm read up on the trusted publisher stuff. Having an early glance it does look that it could make sense.

@flaeppe flaeppe deleted the fix/dependabot branch December 13, 2023 22:13
@flaeppe
Copy link
Copy Markdown
Contributor Author

flaeppe commented Dec 14, 2023

Now that you had mentioned it, we tried to setup it up and had it working with a trusted publisher for our package: https://github.com/5monkeys/bankid-sdk (workflows/release.yaml)

I have to say it was very easy to grasp and get it working. (We used the pending publisher)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants