Skip to content

Configure Dependabot updates for pinned Docker image digests #13048

Description

@brooke-hamilton

Area for Improvement

Radius pins runtime base images by digest for reproducible builds, but the repository's generated Dependabot configuration does not enable the docker ecosystem.

Observed behavior

Pinned Docker image digests must be discovered and refreshed manually. .github/dependabot.yml is synced from radius-project/.github, so a local-only edit in this repository would be overwritten.

Desired behavior

Dependabot regularly proposes digest updates for pinned Docker runtime base images in Radius while preserving the readable image tag next to each digest.

Proposed Fix

Update the authoritative sync configuration in radius-project/.github to add the docker ecosystem for the Radius Dockerfile directories, regenerate or sync .github/dependabot.yml, and verify Dependabot recognizes digest-pinned FROM references.

rad Version

N/A

Operating system

N/A

Additional context

Follow-up to #12922 and review feedback on #12984. Keep the dependency automation change separate from the Debian 13 pin so the source-of-truth organization configuration and generated Radius configuration can be updated together.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

maintenanceIssue is a non-user-facing task like updating tests, improving automation, etc..

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions