diff --git a/PROJECT_ASSESSMENT.md b/PROJECT_ASSESSMENT.md index 5779f41..fca5668 100644 --- a/PROJECT_ASSESSMENT.md +++ b/PROJECT_ASSESSMENT.md @@ -229,7 +229,7 @@ Headlamp v0.39.0 with default `watchPlugins: true` treats catalog-managed plugin **Action Items:** - [ ] Parallelize test execution - [ ] Add npm cache to GitHub Actions -- [ ] Integrate Dependabot +- [x] Renovate is configured org-wide via `github>privilegedescalation/.github:renovate-config` - [ ] Add semantic-release --- diff --git a/SECURITY.md b/SECURITY.md index 122ccd8..aa6ca22 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -212,7 +212,7 @@ If you discover a security vulnerability in this plugin, please report it via: The project uses: - **npm audit**: Runs automatically during `npm install` -- **Dependabot**: GitHub Dependabot monitors dependencies and creates PRs for updates +- **Renovate**: Automated dependency updates via Mend Renovate (org-wide configured) - **GitHub Actions**: CI workflow runs `npm audit` on every commit ### Updating Dependencies