Skip to content

Conversation

@namurphy
Copy link
Member

@namurphy namurphy commented Jan 29, 2026

I added a basic .github/dependabot.yml, adapted from PlasmaPy's but with monthly updates instead of weekly. It includes a dependency cooldown period since this gives a chance for security vulnerabilities to be identified before we start using them.

Closes #27.

@namurphy
Copy link
Member Author

The first updates should be on Monday, which will help me make sure there aren't any configuration problems.

@namurphy namurphy merged commit c22c8a7 into PlasmaPy:main Jan 30, 2026
17 checks passed
@namurphy namurphy deleted the dependabotabotbob branch January 30, 2026 18:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add dependabot configuration to update versions in the GitHub Actions ecosystem

1 participant