Skip to content

Conversation

@mmorel-35
Copy link

@mmorel-35 mmorel-35 commented Dec 7, 2025

What issue is this addressing?

add dependabot configuration and pin action versions in workflows

What type of issue is this addressing?

It is safer to use a git commit version (corresponding to the tag version used) and with dependabot you have a process able to provide you updates on the commit and the tag in comment.

What this PR does | solves

Fixes #374

…flows

Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
@hajimehoshi
Copy link
Member

Before sending a PR, please file an issue to explain what kind of issue there is.

@mmorel-35 mmorel-35 changed the title .github: add dependabot configuration and pin action versions in workflows add dependabot configuration and pin action versions in workflows Dec 7, 2025
@mmorel-35
Copy link
Author

I recommend adopting golangci-lint, it’s the de facto standard Go linter aggregator, CI friendly, and highly configurable.

@hajimehoshi hajimehoshi closed this Dec 8, 2025
@mmorel-35 mmorel-35 deleted the setup-dependabot branch December 8, 2025 07:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Create dependabot configuration and pin GitHub Action versions

2 participants