diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 5203e1a..3d6a1ce 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -13,6 +13,14 @@ updates: directory: / schedule: interval: weekly + # One PR for every github/codeql-action step: CodeQL refuses a workflow + # whose init, analyze and upload-sarif steps run different versions + # ("Loaded a configuration file for version X, but running version Y"), + # so single-step bumps fail on their own (tabellarium #70/#71). + groups: + codeql-action: + patterns: + - github/codeql-action* # The hash-pinned documentation toolchain: pinning keeps a compromised # release out, Dependabot keeps the pin from going stale. - package-ecosystem: pip