Skip to content

Security: Dependabot for pip/uv, GitHub Actions, and npm #47

Description

@caidurbin

What to build

Add Dependabot to keep dependencies and pinned action SHAs current. Configure update ecosystems for Python (pip/uv), GitHub Actions, and npm, with sensible scheduling/grouping. This also keeps the first-party action SHA pins fresh and gives zizmor a Dependabot config to audit.

Acceptance criteria

  • .github/dependabot.yml covers pip/uv, github-actions, and npm
  • Update schedule and grouping configured to limit PR noise
  • Dependabot opens update PRs successfully

Blocked by

None - can start immediately

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependenciesPull requests that update a dependency fileenhancementNew feature or requestready-for-agentFully specified, ready for an AFK agent

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions