dependabot: use directories and use docker ecosystem #4017
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What does this pull request do?
Use
dependabot
for updating docker images stored in our internal docker registry using this.Use
directories
to manage the dependencies for the GitHub workflows and composite actions.Why
We already have secrets stored for accessing the internal docker registry. Use one dependency management tool with native support for GitHub actions and the GH secrets access control.
This has been already tested in the past in a sandbox repository and also in other GH internal repositories.
Actions
Related issues
See elastic/apm-agent-nodejs#4539 and elastic/apm-agent-python#2246
Checklist