Skip to content

Conversation

@MariusStorhaug
Copy link
Member

Dependabot now checks for updates daily with a 7-day cooldown period, reducing noise while maintaining timely security updates. The Process-PSModule workflow is pinned to a specific commit SHA with version comment for enhanced security and reproducibility.

Dependabot Configuration

Updated the schedule from weekly to daily with a cooldown of 7 days. This means Dependabot will check for updates daily but will wait 7 days after a new version is released before creating a PR, helping to avoid early adoption of potentially unstable releases.

schedule:
  interval: daily
cooldown:
  default-days: 7

Pinned Workflows

The reusable workflow is now pinned to a specific commit SHA with version tag comment for traceability:

Workflow Version Commit SHA
PSModule/Process-PSModule v5.4.1 be7d5dcbceec14855d325fdd34f2a7c2f05a7f57

@MariusStorhaug MariusStorhaug changed the title 🩹 Update dependabot schedule and pin workflow to SHA 🩹[Patch]: Update dependabot schedule and pin workflow to SHA Jan 22, 2026
@MariusStorhaug MariusStorhaug marked this pull request as ready for review January 22, 2026 14:29
@MariusStorhaug MariusStorhaug requested a review from a team as a code owner January 22, 2026 14:29
@MariusStorhaug MariusStorhaug merged commit 7898774 into main Jan 22, 2026
2 checks passed
@MariusStorhaug MariusStorhaug deleted the feature/update-dependabot-and-actions branch January 22, 2026 14:47
@github-actions
Copy link

Module Template-PSModule - 0.0.8 published to the PowerShell Gallery.

@github-actions
Copy link

GitHub release for Template-PSModule v0.0.8 has been created.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants