theme-ui icon indicating copy to clipboard operation
theme-ui copied to clipboard

chore: Included githubactions in the dependabot config

Open naveensrinivasan opened this issue 2 years ago • 2 comments

This should help with keeping the GitHub actions updated on new releases. This will also help with keeping it secure.

Dependabot helps in keeping the supply chain secure https://docs.github.com/en/code-security/dependabot

GitHub actions up to date https://docs.github.com/en/code-security/dependabot/working-with-dependabot/keeping-your-actions-up-to-date-with-dependabot

https://github.com/ossf/scorecard/blob/main/docs/checks.md#dependency-update-tool Signed-off-by: naveensrinivasan [email protected]

naveensrinivasan avatar Apr 27 '22 14:04 naveensrinivasan

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Updated
theme-ui ✅ Ready (Inspect) Visit Preview Apr 27, 2022 at 2:12PM (UTC)

vercel[bot] avatar Apr 27 '22 14:04 vercel[bot]

This pull request is automatically built and testable in CodeSandbox.

To see build info of the built libraries, click here or the icon next to each commit SHA.

Latest deployment of this branch, based on commit 2453096581041ee513dc42190921e82b294a5736:

Sandbox Source
system-ui/theme-ui Configuration
gatsby-plugin-theme-ui-example Configuration

codesandbox-ci[bot] avatar Apr 27 '22 14:04 codesandbox-ci[bot]

Hey @naveensrinivasan.

Thank you for the interest in Theme UI. I'm sorry to say that, but we're unfortunately not going to merge this. As a rule of thumb, we are not merging first-time contributors Pull Requests affecting CI.

Our GitHub Actions setup is internal. It doesn't affect the users, but it's a possible vector for attack that can affect them very much.

hasparus avatar Nov 22 '22 04:11 hasparus