Skip to content

Commit 0fd70e6

Browse files
authored
Merge pull request #130 from manics/dependabot-pin-dockerfile
Pin dockerfile SHA, bump monthly with dependabot
2 parents cf07279 + b3a37bb commit 0fd70e6

File tree

2 files changed

+8
-1
lines changed

2 files changed

+8
-1
lines changed

Diff for: .github/dependabot.yaml

+7
Original file line numberDiff line numberDiff line change
@@ -15,3 +15,10 @@ updates:
1515
interval: monthly
1616
time: "05:00"
1717
timezone: Etc/UTC
18+
19+
# Bump dockerfile FROM
20+
- package-ecosystem: docker
21+
directory: /
22+
labels: [dependencies]
23+
schedule:
24+
interval: monthly

Diff for: Dockerfile

+1-1
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM quay.io/jupyter/base-notebook:latest
1+
FROM quay.io/jupyter/base-notebook@sha256:876e3c3e40c4f0a25d3a16223a158a2d582b1ad77ac94269d43a5f6256eb4eec
22

33
USER root
44

0 commit comments

Comments
 (0)