diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..6535247 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,14 @@ +# To get started with Dependabot version updates, you'll need to specify which +# package ecosystems to update and where the package manifests are located. +# Please see the documentation for all configuration options: +# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file + +version: 2 +updates: + # Enable version updates for GitHub Actions + - package-ecosystem: 'github-actions' + # Workflow files stored in the default location of `.github/workflows` + # You don't need to specify `/.github/workflows` for `directory`. You can use `directory: "/"`. + directory: '/' + schedule: + interval: 'weekly' diff --git a/.github/workflows/basic-validation.yml b/.github/workflows/basic-validation.yml index dd45f76..606e6db 100644 --- a/.github/workflows/basic-validation.yml +++ b/.github/workflows/basic-validation.yml @@ -62,7 +62,9 @@ jobs: - name: Test run: npm test + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - name: Audit packages run: npm audit --audit-level=high - if: ${{inputs.enable-audit}} \ No newline at end of file + if: ${{inputs.enable-audit}}