Skip to content

Conversation

@ScottBrenner
Copy link

@ScottBrenner ScottBrenner commented Nov 15, 2025

Description

Noticed some actions used in the workflows here are outdated, proposing a Dependabot configuration to update - reference https://docs.github.com/en/actions/security-guides/using-githubs-security-features-to-secure-your-use-of-github-actions#keeping-the-actions-in-your-workflows-secure-and-up-to-date

Checklist

  • Self-reviewed
  • Added/updated tests (if needed)
  • Updated CHANGELOG.md (if needed)
  • Updated documentation (if needed)

Additional Notes

Suggest enabling https://docs.github.com/en/code-security/dependabot/working-with-dependabot/about-dependabot-on-github-actions-runners#enabling-or-disabling-for-your-repository as well

enoodle
enoodle previously approved these changes Nov 19, 2025
Copy link
Collaborator

@enoodle enoodle left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good, We should also apply this to gomod

@enoodle
Copy link
Collaborator

enoodle commented Nov 19, 2025

@ScottBrenner It wants you to run add a few license lines to the newly created file. you can run ./bin/addlicense -c "NVIDIA CORPORATION" -s=only -l apache . to add it or look at the failed action for the diff.

@ScottBrenner
Copy link
Author

Done & done!

@ScottBrenner ScottBrenner changed the title ci: Dependabot configuration to update actions in workflows ci: Dependabot configuration to update Go modules & actions in workflows Nov 20, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants