-
Notifications
You must be signed in to change notification settings - Fork 41
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
build(deps): bump peter-evans/repository-dispatch from 1 to 2 #1586
build(deps): bump peter-evans/repository-dispatch from 1 to 2 #1586
Conversation
Bumps [peter-evans/repository-dispatch](https://github.com/peter-evans/repository-dispatch) from 1 to 2. - [Release notes](https://github.com/peter-evans/repository-dispatch/releases) - [Commits](peter-evans/repository-dispatch@v1...v2) --- updated-dependencies: - dependency-name: peter-evans/repository-dispatch dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <[email protected]>
Codecov Report
Additional details and impacted files@@ Coverage Diff @@
## main #1586 +/- ##
=======================================
Coverage 81.78% 81.78%
=======================================
Files 158 158
Lines 14759 14759
=======================================
Hits 12071 12071
Misses 2264 2264
Partials 424 424
Flags with carried forward coverage won't be shown. Click here to find out more. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I'd recommend pinning the SHA of any external actions.
+1, this can be addressed separately. Do you @dimakis or @jackdelahunt see any issue with this update? It's the one used to notify the SDK repo of the changes. |
What is the reason for it? I am trying to understand the issue. Dependabot will notify about new changes on them but not automatically upgrade them unless we approve it |
I think this is mentioning the same issues as this PR noted. Even though the version may stay the same things can change. |
What would be the criteria then to decide if an action is trusted or not? |
In the RedHat-developer org we are moving towards trusting GH actions and companies like Docker etc. whilst any solo contributor's action would be a pinned SHA, it comes on advice from the prod sec team |
I don't see any issue, but to be honest I don't know a whole lot about this 🤦 |
Thanks @dimakis From looking at the changelog, it should be safe to merge. |
Bumps peter-evans/repository-dispatch from 1 to 2.
Release notes
Sourced from peter-evans/repository-dispatch's releases.
Commits
26b39ed
Update workflowb155cf1
Update readmefaa2bf0
Update readme0bc97bd
Bump@types/node
from 16.11.11 to 18.11.11 (#134)8ab3ab8
Bump@vercel/ncc
from 0.32.0 to 0.36.0 (#133)defb7de
Bump eslint-plugin-github from 4.3.5 to 4.6.0 (#130)fb1da2a
Bump jest-circus from 27.4.2 to 29.3.1 (#132)ec896de
Bump prettier from 2.5.0 to 2.8.1 (#131)9255d35
Update workflowf8e700e
Add automerge workflowDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)