evergreen icon indicating copy to clipboard operation
evergreen copied to clipboard

GitHub Action to enable automated security updates and open a issue/PR in repos in an org that have dependency files but no dependabot.yaml file

Results 12 evergreen issues
Sort by recently updated
recently updated
newest added

### Is your feature request related to a problem? If you have a `dependabot.yml` with config for e.g. ecosystem `maven`, then add a new ecosystem in the same project (i.e....

enhancement

Enable filtering repositories to run on by team, e.g. run on my organisation just for repos owned by the engineering team

enhancement
keep

The logic to detect whether to configure package updates for most ecosystems, except for GitHub Actions and Terraform only appears to consider files in the root of the repository. I...

bug
ready-for-work
keep

Would be great to implement rate limiting so users don't get failed workflow runs because it was zooming through repos too fast.

enhancement
ready-for-work
keep

Rather than requiring a full list of repos to exclude from Dependabot to be manually maintained, accepting repo labels to ignore would be more scalable.

enhancement
ready-for-work
keep

GitHub Actions provides information about the URLs associated with the GitHub instance running the action, whether that is GitHub.com or GitHub Enterprise Server via the following properties of the [`github`](https://docs.github.com/actions/learn-github-actions/contexts#github-context)...

enhancement
ready-for-work
keep

# Pull Request Fix https://github.com/github/evergreen/issues/168 ## Proposed Changes Set a default value to dependabot_filename_to_use rather than `None` ## Readiness Checklist ### Author/Contributor - [x] If documentation is needed for this...

fix

### Is your feature request related to a problem? When setting up `dependabot.yml` files I typically need to set up at least one private registry, depending on the ecosystems being...

enhancement
ready-for-work
keep