Skip to content

Update GitHub Actions and enable Dependabot#2686

Merged
riccardobl merged 3 commits intojMonkeyEngine:masterfrom
8Keep:github-actions-update
Apr 7, 2026
Merged

Update GitHub Actions and enable Dependabot#2686
riccardobl merged 3 commits intojMonkeyEngine:masterfrom
8Keep:github-actions-update

Conversation

@8Keep
Copy link
Copy Markdown
Contributor

@8Keep 8Keep commented Apr 7, 2026

Updating current github actions and enabling dependabot for github actions from now on.

Copy link
Copy Markdown
Contributor

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the Dependabot configuration to include tracking for GitHub Actions. The new configuration specifies a weekly update schedule, a limit of five open pull requests, a 'ci' commit message prefix, and relevant labels for these dependency updates. I have no feedback to provide as no issues were identified and no review comments were present.

@8Keep 8Keep marked this pull request as ready for review April 7, 2026 03:24
Copy link
Copy Markdown
Member

@riccardobl riccardobl left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!
I took the liberty of making a few changes to this PR:

  • downgraded some GitHub Actions that were released very recently to slightly older versions
  • added a 30 days cooldown to Dependabot

The goal is to avoid tracking the very latest releases immediately, giving some time for potential supply-chain attacks to surface before we upgrade.

@8Keep
Copy link
Copy Markdown
Contributor Author

8Keep commented Apr 7, 2026

Thanks @riccardobl, those changes sound good to me too. I don't think I can merge, let me know when you can do that.

@riccardobl riccardobl merged commit fcfd478 into jMonkeyEngine:master Apr 7, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants