Skip to content

chore: enable Dependabot weekly GitHub Actions bumps#487

Open
hf-dependantbot-rollout[bot] wants to merge 1 commit into
mainfrom
chore/add-dependabot-github-actions
Open

chore: enable Dependabot weekly GitHub Actions bumps#487
hf-dependantbot-rollout[bot] wants to merge 1 commit into
mainfrom
chore/add-dependabot-github-actions

Conversation

@hf-dependantbot-rollout

@hf-dependantbot-rollout hf-dependantbot-rollout Bot commented May 26, 2026

Copy link
Copy Markdown

Summary

Adds .github/dependabot.yml so this repo's pinned GitHub Action SHAs
get bumped automatically once a week.

All action updates are grouped into one weekly PR (not one PR per
action) to keep the noise down, and Dependabot waits 7 days after a
release before opening the bump
(cooldown). The 7-day cooldown is
aligned with the org's pinact min_age: 7 policy — so by the time
the Dependabot PR lands, the SHA is already old enough for the security
gate to accept it. The bot opens the PR; the org-wide security gate
(pinact + denylist + deny-packages + osv-scan) runs on it; a human
merges.

Why

GitHub Action SHAs that were safe when pinned can drift out of date —
missing security patches, bug fixes, or new features. Dependabot keeps
them current. Combined with the org-wide validation workflow (which
blocks compromised SHAs from landing), the bumps are safe by
construction.

Closes huggingface/tracking-issues#599


Note

Low Risk
CI-only configuration; no application code, auth, or runtime behavior changes.

Overview
Introduces Dependabot for the repo via a new .github/dependabot.yml, so pinned GitHub Actions SHAs are proposed for updates on a weekly schedule.

All action bumps are grouped into a single weekly PR (patterns: ["*"]), and a 7-day cooldown after release before Dependabot opens the bump—intended to line up with org pinact min_age: 7 so security gates can accept the new SHAs when the PR lands.

Reviewed by Cursor Bugbot for commit e6aa1df. Bugbot is set up for automated code reviews on this repo. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants