Skip to content

Enable Dependabot or Renovate #56

Description

@christian-byrne

What — No .github/dependabot.yml and no renovate.json.

Why it matters here — Published package — its dependency tree ships to every consumer, and nothing reports a CVE in it. Comfy-Org/comfy-cli already runs Dependabot on a uv project.

Evidence

$ ls .github/dependabot.yml renovate.json .github/renovate.json 2>&1 | tail -1
ls: cannot access '.github/renovate.json': No such file or directory

Fix

Add .github/dependabot.yml for pip/uv and github-actions, weekly.


Found by repo-audit during repo improvement sweep 2026-08-17. Parent: #53

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions