Skip to content

Fixup getopt requires#131

Open
SuperQ wants to merge 1 commit into
oklog:mainfrom
SuperQ:getopt/v2
Open

Fixup getopt requires#131
SuperQ wants to merge 1 commit into
oklog:mainfrom
SuperQ:getopt/v2

Conversation

@SuperQ

@SuperQ SuperQ commented Nov 17, 2025

Copy link
Copy Markdown

Use the correct path and tag for the github.com/pborman/getopt/v2 requirement.

  • Update and pin GitHub actions for supply chain security.
  • Enable dependabot.

@peterbourgon

peterbourgon commented Nov 17, 2025

Copy link
Copy Markdown
Member

Happy to update the dependency, but no thanks on Dependabot, and can you explain the SHA versions for the tooling? At first glance it seems strange...

@SuperQ

SuperQ commented Nov 17, 2025

Copy link
Copy Markdown
Author

The SHA thing is a recommended mitigation against GitHub Action supply chain attacks.

This is why I enabled dependabot, it makes it easier to review the changes for actions by showing the git changes between versions.

Use the correct path and tag for the `github.com/pborman/getopt/v2`
requirement.
* Update and pin GitHub actions for supply chain security.
* Enable dependabot.

Signed-off-by: SuperQ <superq@gmail.com>
@SuperQ

SuperQ commented Nov 17, 2025

Copy link
Copy Markdown
Author

I removed the dependabot config.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants