Skip to content

ci(deps): daily alert-check only (drop weekly bump)#485

Merged
ericfitz merged 1 commit into
mainfrom
chore/deps-daily-alert-only
Jun 19, 2026
Merged

ci(deps): daily alert-check only (drop weekly bump)#485
ericfitz merged 1 commit into
mainfrom
chore/deps-daily-alert-only

Conversation

@ericfitz

Copy link
Copy Markdown
Owner

Per request: no weekly bump; the daily 13:00 UTC job only bumps when open Dependabot alerts exist. discover now mints a GitHub App token to read the alerts API (GITHUB_TOKEN can't). Requires the ericfitz-deps-bot App to have 'Dependabot alerts: read' (accepted on this install).

…ken alert read)

Remove the weekly full-bump cron. The daily 13:00 UTC job now only bumps when
open Dependabot alerts exist. discover mints a GitHub App token to read the
alerts API (GITHUB_TOKEN cannot). Manual workflow_dispatch unchanged.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Q6YFSYL252h71BH5ZL8QqT
@ericfitz ericfitz merged commit 283812b into main Jun 19, 2026
7 checks passed
@ericfitz ericfitz deleted the chore/deps-daily-alert-only branch June 19, 2026 11:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant