| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
| directory: "/" | ||
| schedule: | ||
| interval: weekly | ||
| - package-ecosystem: github-actions |
There was a problem hiding this comment.
Perhaps comment here why we need this separately from the / pattern above. I understand / to mean "repo root and .github/workflows` and any other subdir needs explicit inclusion?
Sorry, something went wrong.
There was a problem hiding this comment.
Yes, that's correct 👍 will do
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
Our Swift extractor is now using Swift v5.7.3, but our setup-swift version was pinned to a prior version that doesn't support v5.7.3, so our CI is failing.
This change bumps setup-swift to its most recent release commit SHA (https://github.com/swift-actions/setup-swift/releases/tag/v1.22.0).
It also adds a new entry to the dependabot.yml file because Dependabot should have bumped this version — setup-swift v1.22.0 was released two weeks ago and we run Dependabot checks weekly. Per the dependabot maintainers, the filepath needed is the root of the repo (/.github/workflows is specially cased under /).
We also add a comment reminding the next person who approves a Dependabot update to manually update the SHA in the CLI's CodeQL Action Integration Test. (Note that we should also replicate the logic of finding the appropriate Swift version in the CLI's integration test).
Merge / deployment checklist