Skip to content

[chore] Add Dependabot configuration for Maven and GitHub Actions#796

Open
dasomel wants to merge 1 commit into
eGovFramework:mainfrom
dasomel-eGovFramework:chore/dependabot-5.0.x
Open

[chore] Add Dependabot configuration for Maven and GitHub Actions#796
dasomel wants to merge 1 commit into
eGovFramework:mainfrom
dasomel-eGovFramework:chore/dependabot-5.0.x

Conversation

@dasomel
Copy link
Copy Markdown
Contributor

@dasomel dasomel commented May 20, 2026

변경 사유

.github/dependabot.yml 미설치로 의존성 버전 관리가 수동입니다. 자동화된 의존성 업데이트 PR을 받을 수 있도록 Dependabot을 활성화합니다.

변경 내용

  • .github/dependabot.yml 신규 추가
    • maven: 주간 스캔, 동시 PR 5개
    • github-actions: 주간 스캔, 동시 PR 3개
    • 스케줄: 매주 월요일 09:00 KST

영향 범위

  • 기존 코드/빌드 영향 없음
  • 머지 후 첫 월요일에 Dependabot 시작

체크리스트

  • 단일 주제
  • 5.0.x 브랜치 대상
  • 기존 동작 미변경

Enable automated dependency update PRs to reduce manual CVE tracking burden.

- Maven: weekly scan, up to 5 open PRs, labeled "dependencies"
- GitHub Actions: weekly scan, up to 3 open PRs, labeled "ci"
- Schedule: every Monday 09:00 KST
@dasomel dasomel changed the base branch from 5.0.x to main May 26, 2026 15:50
@dasomel dasomel changed the title [chore][5.0.x] Add Dependabot configuration for Maven and GitHub Actions [chore] Add Dependabot configuration for Maven and GitHub Actions May 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant