renovatebot / github-action

Other
271 stars 80 forks source link

Dependency Dashboard #31

Open renovate[bot] opened 4 years ago

renovate[bot] commented 4 years ago

This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.

Pending Approval

These branches will be created by Renovate only once you click their checkbox below.

Awaiting Schedule

These updates are awaiting their schedule. Click on a checkbox to get an update now.

Pending Status Checks

These updates await pending status checks. To force their creation now, click the checkbox below.

Detected dependencies

github-actions
.github/workflows/build.yml - `actions/checkout v4.1.7@692973e3d937129bcbf40652eb9f2f61becf3332` - `wagoid/commitlint-github-action v6.1.2@3d28780bbf0365e29b144e272b2121204d5be5f3` - `actions/checkout v4.1.7@692973e3d937129bcbf40652eb9f2f61becf3332` - `actions/setup-node v4.0.4@0a44ba7841725637a19e28fa30b79a866c81b0a6` - `actions/checkout v4.1.7@692973e3d937129bcbf40652eb9f2f61becf3332` - `actions/setup-node v4.0.4@0a44ba7841725637a19e28fa30b79a866c81b0a6` - `actions/checkout v4.1.7@692973e3d937129bcbf40652eb9f2f61becf3332` - `actions/setup-node v4.0.4@0a44ba7841725637a19e28fa30b79a866c81b0a6`
npm
package.json - `@actions/core 1.10.1` - `@actions/exec 1.1.1` - `@commitlint/cli 19.5.0` - `@commitlint/config-conventional 19.5.0` - `@semantic-release/git 10.0.1` - `@semantic-release/github 10.3.4` - `@semantic-release/npm 12.0.1` - `@tsconfig/node20 20.1.4` - `@types/node 20.16.5` - `@typescript-eslint/eslint-plugin 6.21.0` - `@typescript-eslint/parser 6.21.0` - `@vercel/ncc 0.38.1` - `conventional-changelog-conventionalcommits 8.0.0` - `eslint 8.57.1` - `eslint-config-prettier 9.1.0` - `eslint-plugin-json 3.1.0` - `husky 9.1.6` - `lint-staged 15.2.10` - `npm-run-all2 6.2.3` - `prettier 3.3.3` - `prettier-plugin-packagejson 2.5.2` - `rimraf 6.0.1` - `semantic-release 24.1.1` - `ts-node 10.9.2` - `typescript 5.6.2` - `node >=20.9.0` - `pnpm ^9.0.0` - `pnpm 9.10.0`
regex
README.md - `ghcr.io/renovatebot/renovate 38.80.0`
README.md - `actions/checkout v4.1.7` - `renovatebot/github-action v40.2.10` - `actions/checkout v4.1.7` - `renovatebot/github-action v40.2.10` - `actions/checkout v4.1.7` - `renovatebot/github-action v40.2.10` - `actions/checkout v4.1.7` - `renovatebot/github-action v40.2.10` - `actions/checkout v4.1.7` - `renovatebot/github-action v40.2.10` - `actions/checkout v4.1.7` - `renovatebot/github-action v40.2.10` - `actions/checkout v4.1.7` - `renovatebot/github-action v40.2.10` - `renovatebot/github-action v40.2.10` - `actions/checkout v4.1.7` - `renovatebot/github-action v40.2.10` - `renovatebot/github-action v40.2.10` - `actions/checkout v4.1.7` - `renovatebot/github-action v40.2.10` - `actions/checkout v4.1.7` - `renovatebot/github-action v40.2.10` - `renovatebot/github-action v40.2.10` - `renovatebot/github-action v40.2.10`
.github/workflows/build.yml - `renovate 38.94.3`
README.md - `renovatebot/github-action v40.2.10` - `renovatebot/github-action v40.2.10` - `renovatebot/github-action v40.2.10` - `renovatebot/github-action v40.2.10` - `renovatebot/github-action v40.2.10` - `renovatebot/github-action v40.2.10` - `renovatebot/github-action v40.2.10` - `renovatebot/github-action v40.2.10` - `renovatebot/github-action v40.2.10` - `renovatebot/github-action v40.2.10` - `renovatebot/github-action v40.2.10` - `renovatebot/github-action v40.2.10` - `renovatebot/github-action v40.2.10` - `renovatebot/github-action v40.2.10`
README.md - `ghcr.io/renovatebot/renovate 38.80.0` - `ghcr.io/renovatebot/renovate 38.80.0`

jdbruijn commented 4 years ago

@viceice Should "lock file maintenance" be enabled? If so I'll check the checkbox to approve it.

viceice commented 4 years ago

You can approve it, but it will always come back to be un approved after run. We can do lockfile management on manual regular schedule, or if security issues occure, which can be fixed by lockfile maintenance.

jdbruijn commented 4 years ago

So this is just like the rebase checkbox in a PR where you check it once to rebase the PR. I think the lockfile management is only needed when there is a security issue (handled by dependabot if I'm not mistaken). So, we don't need to do anything for it IMHO. Just to check: are security issues enabled for this repository?

viceice commented 3 years ago

actions/setup-node v2 is currently a pre-release