Skip to content

Fix dependabot bumping#1289

Merged
evrardjp merged 1 commit intokubereboot:mainfrom
evrardjp:include-comment-for-dependabot
Mar 24, 2026
Merged

Fix dependabot bumping#1289
evrardjp merged 1 commit intokubereboot:mainfrom
evrardjp:include-comment-for-dependabot

Conversation

@evrardjp
Copy link
Copy Markdown
Collaborator

Since September 2025, dependabot does not update the actions
anymore. Putting in a comment the version tag (next to the
sha) make it clear that the intent is not to pin.

This was not necessary in the past and seem required now.

@evrardjp evrardjp force-pushed the include-comment-for-dependabot branch 2 times, most recently from b339dff to 3cbb406 Compare March 19, 2026 17:34
@evrardjp
Copy link
Copy Markdown
Collaborator Author

Needs #1268 first

Copy link
Copy Markdown
Contributor

@dharsanb dharsanb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested changes due to security incident.
Ref: GHSA-69fq-xp46-6x23

@evrardjp evrardjp dismissed dharsanb’s stale review March 23, 2026 05:51

Code updated based on review. Thanks @dharsanb for the suggestions.

@evrardjp
Copy link
Copy Markdown
Collaborator Author

@evrardjp : you need to regroup and signoff those commits.

Since September 2025, dependabot does not update some actions
anymore. Putting in a comment the _version tag_ (next to the
sha) make it clear that the intent is not to pin and should
allow further bumping by dependabot.

This was not necessary in the past and seem required now.

Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party>
@evrardjp evrardjp force-pushed the include-comment-for-dependabot branch from 42c8447 to ee13c5c Compare March 24, 2026 08:51
@evrardjp
Copy link
Copy Markdown
Collaborator Author

Rebased.

@evrardjp evrardjp merged commit 334fb5f into kubereboot:main Mar 24, 2026
25 checks passed
@evrardjp evrardjp deleted the include-comment-for-dependabot branch March 24, 2026 08:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants