11 Commits

Author SHA1 Message Date
Tim Gross
ecf3d88e81 dependabot: update reviewer for website directory (#25498)
When we updated the codeowner for the website directory to include the "web
presence" group, we didn't also update the dependabot reviewer. This results in
errors in dependabot PRs.

Ref: https://github.com/hashicorp/nomad/pull/25492#issuecomment-2746105976
2025-03-24 12:03:02 -04:00
Tim Gross
db5022b965 deps: remove actions updates from dependabot (#25211)
Dependabot can update actions to versions that are not in the TSCCR
allowlist. The TSCCR check doesn't happen in CE, which means we don't learn we
have a problem until after we've spent the effort to backport them. Remove the
automation that updates actions automatically until this issue is resolved on
the security team's side.
2025-02-25 10:18:50 -05:00
Deniz Onur Duzgun
52f0b40f4c security: fine tune security-scanner to reduce false-positives (#20465)
Resolve scan job runner

Resolve linting alerts

adding EOF on files

adding EOF on gitignore too

add hclfmt and bump action versions

update scan.hcl comments

Co-authored-by: Tim Gross <tgross@hashicorp.com>

fix typo

move scan.hcl file and paths-ignore for scans

change action runner

use org secret to checkout

typo

change runner

use hashicorp/setup-golang@v3

Co-authored-by: Tim Gross <tgross@hashicorp.com>

pin the github action sha
2024-09-18 16:55:39 -04:00
Seth Hoenig
1a4e3a7517 deps: run all dependabot configs over the weekend (#14608) 2022-09-16 10:50:57 -05:00
Michael Schurter
d5ad965857 deps: run dependabot weekly (#13723) 2022-07-12 12:50:09 -07:00
Charlie Voiselle
f233f7446c Quote assignees value to fix dependabot.yaml parsing error (#13372) 2022-06-14 15:07:52 -04:00
Tim Gross
5ef12a6948 website: set dependabot assignees (#12969)
The website build code has been moved out to another repository, so
what's remaining here is local development tooling. Assign these PRs to
the web platform team, but also cut down on the noise we're sending
their way.
2022-06-01 11:40:32 -04:00
Luiz Aoqui
b2b9013e52 dependabot: set proper theme/* labels (#11154) 2021-09-10 09:41:05 -04:00
Kent 'picat' Gruber
0d96ac3748 Add configuration for /api using Go modules 2021-09-03 08:43:05 -04:00
Kent 'picat' Gruber
f05e92562e Add configuration for /website using NPM 2021-07-29 11:03:26 -04:00
Kent 'picat' Gruber
4555392af5 Add initial Dependabot configuration 2021-07-29 10:52:25 -04:00