Skip to content

Disable Dependabot and deprecate this repo#41

Merged
gucci-on-fleek merged 2 commits intomainfrom
issue-35
Feb 4, 2026
Merged

Disable Dependabot and deprecate this repo#41
gucci-on-fleek merged 2 commits intomainfrom
issue-35

Conversation

@gucci-on-fleek
Copy link
Member

As suggested by @norbusan and @muzimuzhi, let's formally deprecate this repo/Action. Also, let's disable Dependabot updates for everything except official GitHub packages to reduce the risk of supply-chain attacks.

Fixes #35.

The risk from supply-chain attacks due to compromised dependencies seems
greater than the risk of attack from out-of-date dependencies for this
Action, so let's disable Dependabot for everything except for official
GitHub Actions dependencies.

See #35.
@gucci-on-fleek gucci-on-fleek merged commit a0af2dd into main Feb 4, 2026
0 of 2 checks passed
@gucci-on-fleek gucci-on-fleek deleted the issue-35 branch February 4, 2026 07:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Disable Dependabot and security alerts?

2 participants