Repository navigation
ci: enable Dependabot version updates for GitHub Actions - #54
Conversation
|
|
|
@codex review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: aed955de0a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
Codex Review: Didn't find any major issues. 🚀 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
Summary
Part of VOL-1094 (epic VOL-1077). volcano-skills had no Dependabot config, so its SHA-pinned actions only moved when someone bumped them by hand. This adds
.github/dependabot.yml.scripts/andtests/use Node built-ins only, so there are no package manifests or lockfiles to watch./, which is.github/workflows(there are no composite actions under.github/actions).open-pull-requests-limit: 5and a 5-day cooldown (Actions supportsdefault-daysonly).ci(deps): …, matching the repo's Conventional Commits history.labels: []stops Dependabot creating its defaults.sync-skills-from-source.mjsexcludes.github/, so this file is never copied into the plugin skill folders and won't trip their drift check.Status (read-only, not changed here)
Validation
check-jsonschema --schemafile https://json.schemastore.org/dependabot-2.0.json .github/dependabot.yml: ok.ci(deps): bump the github-actions group with 2 updates,ci(deps): bump actions/checkout from 4.4.0 to 6.0.0) pass commitlintconfig-conventional.🤖 Generated with Claude Code