Skip to content

Add Dependabot config and CODEOWNERS#2

Merged
SRWieZ merged 1 commit into
mainfrom
harden-workflows
May 19, 2026
Merged

Add Dependabot config and CODEOWNERS#2
SRWieZ merged 1 commit into
mainfrom
harden-workflows

Conversation

@SRWieZ

@SRWieZ SRWieZ commented May 19, 2026

Copy link
Copy Markdown
Owner

Forward-looking baseline ahead of any GitHub Actions workflows landing in this repo. Once workflows exist, Dependabot will keep their pinned SHAs up to date automatically (monthly, grouped, labelled).

Part of the fleet-wide hardening pass triggered by Composer CVE-2026-45793. Same template as knotsphp/publicip#6 (minus the workflow changes that do not apply here yet).

  • Add .github/dependabot.yml (monthly, grouped, labelled)
  • Add .github/CODEOWNERS

Forward-looking baseline ahead of any GitHub Actions workflows landing
in this repo. Once workflows exist, Dependabot will keep their pinned
SHAs up to date automatically (monthly, grouped, labelled).

Part of the fleet-wide hardening pass; same template used across the
knotsphp/* and SRWieZ/* repos.
@SRWieZ SRWieZ merged commit c879d01 into main May 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant