Skip to content

Add Dependabot configuration for dependency updates#16

Open
brinxmat wants to merge 2 commits intov2from
add-dependabot-config
Open

Add Dependabot configuration for dependency updates#16
brinxmat wants to merge 2 commits intov2from
add-dependabot-config

Conversation

@brinxmat
Copy link
Copy Markdown
Contributor

@brinxmat brinxmat commented Apr 1, 2026

Configured Dependabot to update GitHub Actions and Gradle dependencies weekly with specified cooldown and grouping for updates.

Cooldown helps us avoid supply chain attacks.

Note: we should consider renovate since dependabot has gradle issues and I am unconvinced that it supports distributed version catalogues.

Configured Dependabot to update GitHub Actions and Gradle dependencies weekly with specified cooldown and grouping for updates.

Cooldown helps us avoid supply chain attacks.
Removed comments for GitHub Actions and Gradle updates.
@brinxmat brinxmat requested a review from torbjokv April 1, 2026 09:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants