Will Dependabot's updates to the generated file (`~.lock.yml`) work?
Open
community
dependabot
dependencies
question
workflows
- Dominant language
- Go
- Stars
- 5.1k
- Forks
- 541
- Avg merge
- 5h 46m
- Merged PRs (30d)
- 760
Description
I found out that dependabot can update the generated `~.lock.yml` files, bumping dependencies (usually github action versions).
Will that work or should this be flagged within the dependabot team to ignore those files?
Contributor guide
Assessment
This issue has not been assessed yet.