Add dependabot, update GitHub Actions #672
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Fixes #671.
This PR sets up dependabot to keep the repo's Actions up-to-date whenever a new major version is released for the Actions.
Dependabot is set up to only scan once a month and, should it find anything, all Actions with new versions will be updated in a single PR (see this PR as an example).
I've also gone ahead and updated the Actions to the latest major versions. In the case of
coverallsapp/github-action
, I changed it from@master
to@v2
(the latest major version) to protect Jansson from a potential broken HEAD commit in that Action. I can't do the same for theoss-fuzz
Actions because they must be@master
to work properly.