Skip to content

Conversation

@sdn4z
Copy link
Collaborator

@sdn4z sdn4z commented Nov 7, 2025

Dependabot does not work with uv, which means not only that we don't get automatic package updates but also that we don't get alerts on vulnerabilities.

With this scheduled pipeline, osv will run once a week checking for possible threats.

@github-actions github-actions bot added the CI label Nov 7, 2025
@sdn4z sdn4z force-pushed the periodically-run-osv branch from e7b8f43 to b0efcfe Compare November 7, 2025 09:21
@github-actions github-actions bot added CI and removed CI labels Nov 7, 2025
@sdn4z sdn4z marked this pull request as ready for review November 7, 2025 09:27
@sdn4z sdn4z requested a review from scastlara as a code owner November 7, 2025 09:27
@sdn4z sdn4z merged commit 729a9f0 into elementsinteractive:main Nov 7, 2025
13 checks passed
@sdn4z sdn4z deleted the periodically-run-osv branch November 7, 2025 09:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant