Skip to content
This repository was archived by the owner on Mar 26, 2026. It is now read-only.

Add Dependabot config#35

Open
vitbokisch wants to merge 2 commits into
mainfrom
add-dependabot
Open

Add Dependabot config#35
vitbokisch wants to merge 2 commits into
mainfrom
add-dependabot

Conversation

@vitbokisch
Copy link
Copy Markdown
Contributor

Summary

  • Add .github/dependabot.yml for weekly npm + GitHub Actions updates
  • Groups @pyreon, @TanStack, @vitus-labs updates together
  • Resolves DependencyUpdateToolID scorecard alert

Remaining scorecard alerts (FuzzingID, CIIBestPracticesID, MaintainedID, CodeReviewID) are repo settings or not applicable. PinnedDependenciesID + SecurityPolicyID will clear on next scorecard run (already fixed in PR #32).

🤖 Generated with Claude Code

vitbokisch and others added 2 commits March 25, 2026 10:04
Weekly checks for npm and GitHub Actions deps.
Groups @pyreon/*, @tanstack/*, @vitus-labs/* updates together.
Resolves OpenSSF Scorecard DependencyUpdateToolID alert.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Bump all core @pyreon/* to ^0.7.12 (fixed types).
Fix useLink() ref: HTMLElement → HTMLAnchorElement, remove as any cast.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant