Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This is a nice automated tool to keep the various GitHub Actions dependencies up-to-date without needing to monitor them.
E.g., I noticed we are on v4 of this action which has current 'latest' version v6:
data.table/.github/workflows/rchk.yaml
Line 36 in 458d12a
Example dependabot PR from {lintr}:
r-lib/lintr#2992
It's generally a good idea to scan the update log -- an automation tool like this introduces some risk of getting exposed to a security issue (while also removing the security risk of continuing to use versions with known flaws). The actions we use are among the highest-volume actions, so I think that risk is low.
Documentation: https://github.com/dependabot/dependabot-core?tab=readme-ov-file
I already enabled this in the repo settings.