From c67dfa7152e320e55ba3e84c5b51fda8b4e0d516 Mon Sep 17 00:00:00 2001 From: Damien Goutte-Gattat Date: Wed, 23 Sep 2026 23:46:59 +0100 Subject: [PATCH] Add option to enable Dependabot on a repository. Add a project-level configuration option `enable_dependabot`. If set to True, this will result in a Dependabot configuration file (`.github/dependabot.yml`) to monitor the Github Actions used in Github Actions workflows. --- src/incatools/odk/model.py | 6 ++++++ src/incatools/odk/templates/_dynamic_workflows.jinja2 | 9 +++++++++ 2 files changed, 15 insertions(+) diff --git a/src/incatools/odk/model.py b/src/incatools/odk/model.py index 624c945..8166de1 100644 --- a/src/incatools/odk/model.py +++ b/src/incatools/odk/model.py @@ -1155,6 +1155,12 @@ class OntologyProject(JsonSchemaMixin): Currently available workflows: docs, diff, qc, release-diff. """ + enable_dependabot: bool = False + """Enables Dependabot alerts for outdated GitHub Actions. + + This is only meaningful if `ci` is set to `github_actions`. + """ + import_pattern_ontology: bool = False """Imports the DOSDP-derived pattern.owl file into the ontology.""" diff --git a/src/incatools/odk/templates/_dynamic_workflows.jinja2 b/src/incatools/odk/templates/_dynamic_workflows.jinja2 index d18f8cd..1131995 100644 --- a/src/incatools/odk/templates/_dynamic_workflows.jinja2 +++ b/src/incatools/odk/templates/_dynamic_workflows.jinja2 @@ -52,6 +52,15 @@ ontology_qc: - make ROBOT_ENV='ROBOT_JAVA_ARGS=-Xmx6G' test IMP=false PAT=false {% endif %}{# ! 'gitlab-ci' in project.ci -#} {% if 'github_actions' in project.ci -%} +{% if project.enable_dependabot -%} +^^^ .github/dependabot.yml +version: 2 +updates: + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" +{% endif -%} {% if 'qc' in project.workflows -%} ^^^ .github/workflows/qc.yml # Basic ODK workflow