CROSSINGTUD / CryptoAnalysis

CogniCrypt_SAST: CrySL-to-Static Analysis Compiler
Eclipse Public License 2.0
63 stars 39 forks source link

change execution context of the dependabot automerge workflow #708

Closed swissiety closed 2 weeks ago

swissiety commented 2 weeks ago

trigger on pull_request_target to get context of base branch and only…on pom change i.e. allow only pom to change by dependabot

if that still has permissions issues - see https://stackoverflow.com/questions/70664840/automatic-merging-of-dependabot-generated-pull-request-with-codeowners-file-and