-
-
Notifications
You must be signed in to change notification settings - Fork 8
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore: Configure Renovate #1256
Conversation
534dea6
to
cd30c98
Compare
7eacdd5
to
3a827bb
Compare
New, updated, and removed dependencies detected. Learn more about Socket for GitHub ↗︎
🚮 Removed packages: pypi/[email protected] |
Codecov ReportAll modified and coverable lines are covered by tests ✅
✅ All tests successful. No failed tests found. Additional details and impacted files@@ Coverage Diff @@
## main #1256 +/- ##
=========================================
Coverage 100.00% 100.00%
=========================================
Files 10 10
Lines 495 495
Branches 13 13
=========================================
Hits 495 495
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. |
c240771
to
7228952
Compare
7228952
to
f16d42c
Compare
🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎ To accept the risk, merge this PR and you will not be notified again.
Next stepsWhat is a license policy violation?This package is not allowed per your license policy. Review the package's license to ensure compliance. Find a package that does not violate your license policy or adjust your policy to allow this package's license. Take a deeper look at the dependencyTake a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev. Remove the packageIf you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency. Mark a package as acceptable riskTo ignore an alert, reply with a comment starting with
|
6f89d20
to
df70eba
Compare
|
Welcome to Renovate! This is an onboarding PR to help you understand and configure settings before regular Pull Requests begin.
🚦 To activate Renovate, merge this Pull Request. To disable Renovate, simply close this Pull Request unmerged.
Detected Package Files
.circleci/config.yml
(circleci)tests/compose.git-ref.yaml
(docker-compose)tests/compose.mysql.yaml
(docker-compose)tests/compose.yaml
(docker-compose).github/actions/install-tools/action.yml
(github-actions).github/workflows/api-changes.yml
(github-actions).github/workflows/build.yml
(github-actions).github/workflows/gen-release-pr.yml
(github-actions).github/workflows/pr-preview-links.yml
(github-actions).github/workflows/scorecard.yml
(github-actions).github/workflows/tests.yml
(github-actions).github/workflows/zizmor.yml
(github-actions)pyproject.toml
(pep621).pre-commit-config.yaml
(pre-commit).github/workflows/api-changes.yml
(regex).github/workflows/tests.yml
(regex).github/workflows/zizmor.yml
(regex).github/workflows/tests.yml
(regex)Configuration Summary
Based on the default config's presets, Renovate will:
fix
for dependencies andchore
for all others if semantic commits are in use.node_modules
,bower_components
,vendor
and various test/tests (except for nuget) directories._VERSION
environment variables in GitHub Action files.🔡 Do you want to change how Renovate upgrades your dependencies? Add your custom config to
renovate.json
in this branch. Renovate will update the Pull Request description the next time it runs.What to Expect
With your current configuration, Renovate will create 12 Pull Requests:
chore(deps): update dependency zizmor to v1.2.2
renovate/zizmor-1.x
main
1.2.2
chore(deps): update github/codeql-action action to v3.28.3
renovate/github-codeql-action-3.x
main
dd196fa9ce80b6bacc74ca1c32bd5b0ba22efca7
chore(deps): update uv-version to v0.5.22
renovate/uv-version
main
0.5.22
0.5.22
chore(deps): update actions/attest-build-provenance action to v2.2.0
renovate/actions-attest-build-provenance-2.x
main
520d128f165991a6c774bcb264f323e3d70747f4
chore(deps): update astral-sh/setup-uv action to v5.2.1
renovate/astral-sh-setup-uv-5.x
main
b5f58b2abc5763ade55e4e9d0fe52cd1ff7979ca
chore(deps): update cimg/python docker tag to v3.13.1
renovate/cimg-python-3.x
main
3.13.1
chore(deps): update codecov/codecov-action action to v5.2.0
renovate/codecov-codecov-action-5.x
main
5a605bd92782ce0810fa3b8acc235c921b497052
chore(deps): update dependency python to v2.2.0
renovate/python-2.x
main
2.2.0
chore(deps): update hynek/build-and-inspect-python-package action to v2.12.0
renovate/hynek-build-and-inspect-python-package-2.x
main
b5076c307dc91924a82ad150cdd1533b444d3310
chore(deps): update pre-commit hook codespell-project/codespell to v2.4.0
renovate/codespell-project-codespell-2.x
main
v2.4.0
chore(deps): update dependency python to v3
renovate/python-3.x
main
3.0.0
chore(deps): lock file maintenance
renovate/lock-file-maintenance
main
❓ Got questions? Check out Renovate's Docs, particularly the Getting Started section.
If you need any further assistance then you can also request help here.
This PR was generated by Mend Renovate. View the repository job log.