Skip to content

Commit ef31a66

Browse files
authored
Update github-actions-policy.md added a note about dependabot
1 parent 86a9b3e commit ef31a66

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

content/pages/github-actions-policy.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,9 @@ For details on the use of requirement level terms, see the <a href="https://www.
77

88
For additional advice on how to use this feature safely, see <a href="https://cwiki.apache.org/confluence/display/BUILDS/GitHub+Actions+Security" target="_blank">GitHub Actions Security</a>.
99

10+
### Dependabot
11+
All repositories using GitHub Actions **must** have dependabot enabled.
12+
1013
### Resource use
1114
Due to misconfigurations in their builds, some projects have been using unsupportable numbers of [GitHub Actions](github-actions-secrets.html). As part of fixing this situation, Infra has established a policy for GitHub Actions use:
1215

0 commit comments

Comments
 (0)