diff --git a/renovate.json b/renovate.json new file mode 100644 index 0000000..d9ebaee --- /dev/null +++ b/renovate.json @@ -0,0 +1,18 @@ +{ + "$schema": "https://docs.renovatebot.com/renovate-schema.json", + "extends": [ + "config:recommended" + ], + "packageRules": [ + { + "description": "Security hardening for GitHub Actions (FIS-17871): pin to SHA digests, delay updates 3 days", + "matchManagers": [ + "github-actions" + ], + "groupName": "GitHub Actions", + "minimumReleaseAge": "3 days", + "pinDigests": true + } + ] +} +