Skip to content

Commit b9ba748

Browse files
authored
Create dependabot.yaml
This PR adds a Dependabot configuration (dependabot.yml) to automatically keep GitHub Actions up to date. Enabling Dependabot helps ensure the repository remains secure, follows best practices, and stays aligned with Qualcomm engineering standards. Key details: Enables Dependabot for the GitHub Actions ecosystem Scans the root directory (/) where workflows are located Schedules checks to run daily Automates version update PRs for workflow dependencies This improves repository maintainability and helps proactively identify outdated or vulnerable GitHub Actions. Signed-off-by: Sandhya Adavikolanu <sadaviko@qti.qualcomm.com>
1 parent 8969a32 commit b9ba748

1 file changed

Lines changed: 11 additions & 0 deletions

File tree

.github/dependabot.yaml

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
# To get started with Dependabot version updates, you'll need to specify which
2+
# package ecosystems to update and where the package manifests are located.
3+
# Please see the documentation for all configuration options:
4+
# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file
5+
6+
version: 2
7+
updates:
8+
- package-ecosystem: "github-actions" # See documentation for possible values
9+
directory: "/" # This points to .github/workflows
10+
schedule:
11+
interval: "daily"

0 commit comments

Comments
 (0)