Closed dependabot[bot] closed 3 months ago
@bjhargrave dependabot has a way to group these updates so we can get 1 PR that updates all dependencies in a given category. That would be nice to add so these updates become a little less frequent / noisy
dependabot has a way to group these updates
I imagine it wont change much. I don't often see multiple updates for a repo in a given day. Perhaps you are just seeing a single dependency getting multiple PRs, one for each repo, and grouping cannot help that.
dependabot has a way to group these updates
I imagine it wont change much. I don't often see multiple updates for a repo in a given day. Perhaps you are just seeing a single dependency getting multiple PRs, one for each repo, and grouping cannot help that.
Yeah, you're probably right.
I think it'll be more important if we turn it on for requirements.txt on repos with a larger dependency set
Bumps step-security/harden-runner from 2.8.0 to 2.8.1.
Release notes
Sourced from step-security/harden-runner's releases.
Commits
17d0e2b
Merge pull request #425 from step-security/rc-9bb112d0
Update isGitHubHosted implementationf4f3f44
Merge pull request #407 from step-security/dependabot/github_actions/actions/...7a946b5
Bump actions/dependency-review-action from 3.1.3 to 4.3.275a01c2
Merge pull request #417 from step-security/dependabot/github_actions/step-sec...53413f1
Bump step-security/harden-runner from 2.7.1 to 2.8.0Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show