From cb5fb4facef6419f9b3b3b47da7ce7a12bb37023 Mon Sep 17 00:00:00 2001 From: Larry Laski Date: Tue, 15 Aug 2023 20:29:27 -0400 Subject: [PATCH 1/3] PR Review action, dependabot config --- .github/workflows/dependabot.yml | 0 .github/workflows/pull-request-review.yml | 19 +++++++++++++++++++ 2 files changed, 19 insertions(+) create mode 100644 .github/workflows/dependabot.yml create mode 100644 .github/workflows/pull-request-review.yml diff --git a/.github/workflows/dependabot.yml b/.github/workflows/dependabot.yml new file mode 100644 index 0000000..e69de29 diff --git a/.github/workflows/pull-request-review.yml b/.github/workflows/pull-request-review.yml new file mode 100644 index 0000000..9431eb2 --- /dev/null +++ b/.github/workflows/pull-request-review.yml @@ -0,0 +1,19 @@ +name: Pull Request Review + +on: + pull_request: + +jobs: + dependency-review: + runs-on: ubuntu-latest + + name: Dependency Review + + steps: + - name: Checkout code + uses: actions/checkout@v3 + + - name: "Dependency Review" + uses: actions/dependency-review-action@v3 # https://github.com/marketplace/actions/dependency-review + with: + fail-on-severity: moderate From 41e8b5758ea2301d0bd653ef7bb1d8bc16117865 Mon Sep 17 00:00:00 2001 From: Larry Laski Date: Tue, 15 Aug 2023 20:31:54 -0400 Subject: [PATCH 2/3] Added codeowners file --- CODEOWNERS | 1 + 1 file changed, 1 insertion(+) create mode 100644 CODEOWNERS diff --git a/CODEOWNERS b/CODEOWNERS new file mode 100644 index 0000000..f656833 --- /dev/null +++ b/CODEOWNERS @@ -0,0 +1 @@ +* @llaski \ No newline at end of file From 20bb59633e75d1b3466d80f76bf3a8316830f88b Mon Sep 17 00:00:00 2001 From: Larry Laski Date: Tue, 15 Aug 2023 20:35:15 -0400 Subject: [PATCH 3/3] dependabot file location fix --- .github/dependabot.yml | 22 ++++++++++++++++++++++ .github/workflows/dependabot.yml | 0 2 files changed, 22 insertions(+) create mode 100644 .github/dependabot.yml delete mode 100644 .github/workflows/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..338d19f --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,22 @@ +# To get started with Dependabot version updates, you'll need to specify which +# package ecosystems to update and where the package manifests are located. +# Please see the documentation for all configuration options: +# https://docs.github.com/github/administering-a-repository/configuration-options-for-dependency-updates + +version: 2 + +updates: + - package-ecosystem: "composer" # See documentation for possible values + directory: "/" # Location of package manifests + schedule: + interval: "weekly" + + - package-ecosystem: "npm" # See documentation for possible values + directory: "/" # Location of package manifests + schedule: + interval: "weekly" + + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "monthly" diff --git a/.github/workflows/dependabot.yml b/.github/workflows/dependabot.yml deleted file mode 100644 index e69de29..0000000