Dependabot will now create pull requests when new Docker images, dependencies or GitHub actions become available. By fixing the base image tag, we always exactly know what base image we are using and Dependabot will propose updates.
This will reduce the probability of accumulating known vulnerabilities, like suggested in #403
Dependabot will now create pull requests when new Docker images, dependencies or GitHub actions become available. By fixing the base image tag, we always exactly know what base image we are using and Dependabot will propose updates.
This will reduce the probability of accumulating known vulnerabilities, like suggested in #403