ppkarwasz opened a new pull request, #4287: URL: https://github.com/apache/logging-log4j2/pull/4287
Adds `.github/workflows/analyze-dependabot.yaml` to `main`, so that Dependabot PRs against `main` get the same analysis as those against `2.x`. The `pull_request` trigger runs the workflow file from the PR merge commit, so each branch that Dependabot targets needs its own copy. The follow-up `Dependabot Process PR` workflow is triggered by `workflow_run`, which GitHub only evaluates on the default branch, so no copy of it is needed here: the one on `2.x` handles PRs against every branch. The file is identical to the `2.x` version apart from a comment explaining the above. The reusable workflow in `logging-parent` takes no inputs, so nothing is branch-specific. > [!NOTE] > Depends on #4284, which teaches the `2.x` copy of `Dependabot Process PR` to use `src/changelog/.3.x.x` for PRs against `main`. Until it is merged, a Dependabot PR against `main` would get its changelog entry written to `src/changelog/.2.x.x`, which does not exist on `main`. No changelog entry, since this only touches CI configuration. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_014QXFCr2hQv3zoVf7wo5Lab -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
