mirror of
https://github.com/guillaumemeyer/watermarks-remover.git
synced 2026-08-22 13:11:57 +02:00
- dependabot.yml: weekly updates for GitHub Actions (rotates the SHA pins), root pip deps (requirements-dev.txt), and the scorer requirements (compatibility-coupled to the pinned upstream commit — human re-verify noted), monthly for the digest-pinned Docker base image. - CODEOWNERS: keep the default maintainer ownership and make ownership of /.github and SECURITY.md explicit.
42 lines
1.5 KiB
YAML
42 lines
1.5 KiB
YAML
# Dependabot configuration (https://docs.github.com/code-security/dependabot)
|
|
version: 2
|
|
updates:
|
|
# GitHub Actions: keeps the SHA pins in .github/workflows/ fresh. All action
|
|
# references are SHA-pinned, so dependabot is the mechanism that rotates them
|
|
# when upstream releases new versions.
|
|
- package-ecosystem: "github-actions"
|
|
directory: "/"
|
|
schedule:
|
|
interval: "weekly"
|
|
day: "monday"
|
|
open-pull-requests-limit: 5
|
|
|
|
# Root dev/test dependencies (requirements-dev.txt: pytest, pip-audit).
|
|
- package-ecosystem: "pip"
|
|
directory: "/"
|
|
schedule:
|
|
interval: "weekly"
|
|
day: "monday"
|
|
open-pull-requests-limit: 10
|
|
|
|
# Optional reverse-SynthID scorer dependencies. NOTE: these pins are
|
|
# compatibility-coupled to the upstream checkout pinned in
|
|
# setup_synthid.sh / Dockerfile.synthid (REVERSE_SYNTHID_REF). Before merging
|
|
# a bump, re-verify the scorer against that upstream commit — CI's pip-audit
|
|
# step will flag any security regression, but functional compatibility must
|
|
# be checked by a human.
|
|
- package-ecosystem: "pip"
|
|
directory: "/skills/remove-ai-marks/scripts"
|
|
schedule:
|
|
interval: "weekly"
|
|
day: "monday"
|
|
open-pull-requests-limit: 10
|
|
|
|
# Docker base image (Dockerfile.synthid): tracks the digest-pinned
|
|
# python:3.11-slim base. Monthly — digest churn is low-signal weekly.
|
|
- package-ecosystem: "docker"
|
|
directory: "/"
|
|
schedule:
|
|
interval: "monthly"
|
|
open-pull-requests-limit: 5
|