You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
As far as dependabot.yml sections go, package-ecosystem: maven should always be included (except for Gradle-based plugins, of which there are very few), but package-ecosystem: github-actions should only be included if the plugin has a Release Drafter (not inherited from the organization wide one, as should be the case for automated release) and/or Jenkins Security Scan workflow enabled. If the plugin has a .mvn_exec_node or .mvn_exec_yarn file, package-system: npm could be included as in e.g. active-choices-plugin.
Many plugins are missing
.github/dependabot.yml
, so their dependencies are never updated. If needed, this file should be added per the archetype.The text was updated successfully, but these errors were encountered: