@eht16 commented on this pull request.


In .github/dependabot.yml:

> @@ -0,0 +1,6 @@
+version: 2
+updates:
⬇️ Suggested change
-updates:
+updates:
+  # Before applying suggested PRs, make sure that the new versions of any updated actions are allowed in https://github.com/organizations/geany/settings/actions. Versions are pinned and restricted for security reasons.

Can we maybe add the above comment, so that at least in the Dependabot job description we have a hint that versions of the allowed Actions are pinned in the organization settings.


Reply to this email directly, view it on GitHub, or unsubscribe.
You are receiving this because you are subscribed to this thread.Message ID: <geany/geany/pull/3758/review/1874955227@github.com>