Add Dependabot config for GitHub Actions #31119
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
We have some 3rd party GitHub Actions we're pinning for determinism and security, however we'd also like these pinned actions to stay up to date in a controlled fashion. This PR adds Dependabot for Github actions.
For example of recent pinnings, see:
Initial reviewers are a mix of security and internal tools folks, chosen to triage the first couple rounds of updates. I plan on handling these mostly myself, but I'd like to keep the other folks aware.
I chose not to add a language group for these yet, as I'd rather deal with each update individually while we get GHA dependency management ship-shape.
Contributes to https://github.com/gravitational/SecOps/issues/403
Testing Done
I added a version of this in https://github.com/wadells/teleport. You can see an example PR it opened here:
wadells#15