Commit c26da41
committed
fix(dependabot): fix broken config and add cooldown
- Remove private registry config for npm.pkg.github.com as internal
packages are now accessible without a token (CI-1040)
- Add github-actions ecosystem to allow updating internal actions
- Add 7-day cooldown to npm and github-actions to mitigate supply
chain attacks (CI-1108)
Co-Authored-By: opencode noreply@opencode.ai1 parent 3516d09 commit c26da41
1 file changed
+11
-8
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | | - | |
3 | | - | |
4 | | - | |
5 | | - | |
6 | | - | |
7 | | - | |
8 | 2 | | |
9 | 3 | | |
10 | 4 | | |
| |||
14 | 8 | | |
15 | 9 | | |
16 | 10 | | |
17 | | - | |
18 | | - | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
0 commit comments