Skip to content

Security alerts mitigation#11

Merged
trotro merged 3 commits intomainfrom
trotro-patch-1
Mar 17, 2026
Merged

Security alerts mitigation#11
trotro merged 3 commits intomainfrom
trotro-patch-1

Conversation

@trotro
Copy link
Collaborator

@trotro trotro commented Mar 17, 2026

This pull request introduces configuration updates to improve automation and security for the repository. The main changes are the addition of a Dependabot configuration file and an update to permissions in the CodeQL workflow.

Automation and dependency management:

  • Added a .github/dependabot.yml file to enable automatic weekly updates for GitHub Actions and Python dependencies in the /docs directory.

Security and workflow improvements:

  • Updated the .github/workflows/codeql.yml workflow to explicitly set permissions: read-all, improving clarity and security of workflow permissions.

@trotro trotro changed the title Update codeql.yml Security alerts mitigation Mar 17, 2026
@trotro trotro merged commit 7ded79e into main Mar 17, 2026
6 checks passed
@trotro trotro deleted the trotro-patch-1 branch March 17, 2026 17:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant