From a7ab0abda98203a4de066d8c941e4c07593e2440 Mon Sep 17 00:00:00 2001 From: Paul Barrett Date: Mon, 24 Aug 2026 19:18:45 +0100 Subject: [PATCH] ci: keep the GitHub Actions versions current with Dependabot The workflow pins actions/checkout@v4 and actions/setup-python@v5, and nothing tells us when those go stale. The failure mode is a deprecated action or runner image breaking CI on an unrelated PR, which is the worst moment to discover it. Monthly, grouped into a single PR so it is one review rather than a trickle. No Python ecosystem entry, and the config records why: there is no requirements.txt or pyproject.toml to track. pytest is a host-side developer tool and the nodes run MicroPython flashed to the board, not installed packages. Co-Authored-By: Claude Opus 5 --- .github/dependabot.yml | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..4203a76 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,21 @@ +version: 2 + +updates: + # GitHub Actions used by .github/workflows/ci.yml. Pinned major tags go stale + # quietly — a deprecated runner image or action version fails CI on an unrelated + # PR, which is the worst time to find out. + - package-ecosystem: github-actions + directory: / + schedule: + interval: monthly + commit-message: + prefix: "ci" + groups: + actions: + patterns: + - "*" + +# No Python ecosystem entry: there is no requirements.txt or pyproject.toml. +# pytest is a host-side developer tool, and the nodes run MicroPython flashed to +# the board rather than installed packages. Add a pip entry here if a pinned +# dependency file ever lands.