We recently found (in Renovate) some edge cases with how tags work in GitHub Actions which was fun (https://news.ycombinator.com/item?id=47892740) and there's a few things in there Dependabot doesn't seem to support too
To make matters worse, you'd lose getting alerts on vulnerabilities. Dependabot won't send them, and neither will Renovate last time I checked.
- raises PRs for security fixes immediately, regardless of cooldown configs
- flags the PRs as security fixes
- does the above when actions are pinned by commit SHA
? If so, mind sharing some documentation and examples please? I don't mind being proven wrong, but I genuinely couldn't find anything that demonstrates this happens. Dependabot docs actually point to the contrary (see my blog posts).
Zizmor recently shipped a rule to warn of such actions, but it only does it for two known actions so far.