Skip to content

Conversation

@kou
Copy link
Contributor

@kou kou commented Nov 14, 2025

Our workflows use old GitHub Actions. For example, we use actions/checkout@v3 but actions/checkout@v5 is the latest version:

- uses: actions/checkout@v3

https://github.com/actions/checkout/releases

How about enabling Dependabot? If we enable Dependabot, Dependabot opens PRs that update old GitHub Actions.

Dependabot document:
https://docs.github.com/en/code-security/dependabot

Dependabot configuration document:
https://docs.github.com/en/code-security/dependabot/working-with-dependabot/dependabot-options-reference

Our workflows use old GitHub Actions. For example, we use
`actions/checkout@v3` but `actions/checkout@v5` is the latest version:

https://github.com/google/flatbuffers/blob/599847236c35fa3802ea4e46e20e93a55d3a4a94/.github/workflows/build.yml#L33

https://github.com/actions/checkout/releases

How about enabling Dependabot? If we enable Dependabot, Dependabot
opens PRs that update old GitHub Actions.

Dependabot document:
https://docs.github.com/en/code-security/dependabot

Dependabot configuration document:
https://docs.github.com/en/code-security/dependabot/working-with-dependabot/dependabot-options-reference
@github-actions github-actions bot added the CI Continuous Integration label Nov 14, 2025
@jtdavis777
Copy link
Collaborator

@bjornharrtell I noticed you were interacting with dependabot recently, is this something you could comment on?

@bjornharrtell
Copy link
Collaborator

@jtdavis777 not sure what you mean with interacting, it wasn't concious. :) That said, I don't see why not... except that flatbuffers as a project seem to lack maintainers/time, so it might increase burden.

@jtdavis777
Copy link
Collaborator

ah I had just seen that you had approved #8779 and I think merged a different PR into that branch. I'm unsure who (of the active participants :D ) has experience and authority with the CI

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CI Continuous Integration

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants