github / github/gh-aw

Will Dependabot's updates to the generated file (`~.lock.yml`) work?

Open
#19,194 5 comments 0 reactions 0 assignees View on GitHub
community dependabot dependencies question workflows
Dominant language
Go
Stars
5.1k
Forks
541
Avg merge
5h 46m
Merged PRs (30d)
760

Description

I found out that dependabot can update the generated `~.lock.yml` files, bumping dependencies (usually github action versions).

Will that work or should this be flagged within the dependabot team to ignore those files?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.