Add Dependabot and update GitHub Action

Add Dependabot configuration for weekly GitHub Actions updates and
upgrade the `peter-evans/create-or-update-comment` action to `v4`.

This ensures our GitHub Actions dependencies are automatically kept
up-to-date with security patches and new features.
This commit is contained in:
Robbie Blaine 2025-05-11 12:32:55 +02:00
parent fe3283f3b0
commit b5430c7134
No known key found for this signature in database
GPG key ID: 4110110C2C38B0C1
2 changed files with 13 additions and 1 deletions

12
.github/dependabot.yml vendored Normal file
View file

@ -0,0 +1,12 @@
# To get started with Dependabot version updates, you'll need to specify which
# package ecosystems to update and where the package manifests are located.
# Please see the documentation for all configuration options:
# https://docs.github.com/github/administering-a-repository/configuration-options-for-dependency-updates
version: 2
updates:
# Maintain dependencies for GitHub Actions
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly

View file

@ -10,7 +10,7 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Bounty explanation
uses: peter-evans/create-or-update-comment@v3
uses: peter-evans/create-or-update-comment@v4
if: github.event.label.name == '💰bounty'
with:
token: ${{ secrets.GITHUB_TOKEN }}