diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..33f5105 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,21 @@ +version: 2 + +updates: + # Actions referenced by .github/workflows/*.yml. `directory: /` is correct + # here: the github-actions ecosystem always scans .github/workflows. + - package-ecosystem: github-actions + directory: / + schedule: + interval: weekly + day: monday + time: "00:00" + timezone: Etc/UTC + open-pull-requests-limit: 1 + groups: + github-actions: + patterns: + - "*" + update-types: + - major + - minor + - patch diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index 7530c72..cd70120 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -74,8 +74,8 @@ jobs: name: Build PDF runs-on: ubuntu-latest # Pinned by digest so a future texlive/texlive:latest push cannot - # silently change the rendered PDF or break the build. - # Digest as of 2026-05-10 (texlive/texlive:latest). + # silently change the rendered PDF or break the build. Bumped by + # hand; digest taken 2026-05-10. container: texlive/texlive@sha256:a38949128a1828f251bb5b4b2ec945644eb4962ce3adae1996f5edc839629bd1 timeout-minutes: 30 steps: