theupdateframework / tuf-on-ci

A TUF repository and signing tool
Other
20 stars 11 forks source link

dependabot: Reorder pip entries #307

Closed jku closed 3 months ago

jku commented 4 months ago

The aim is to get dependabot to actually skip /repo/install/ because this is managed by update-pinned-deps.yml: Currently the pyproject-dependencies group will catch these deps as well and we don't want that.

If this does not work, we'll have to move the pinning file out of /repo/ completely.