From aa5d93d79c1b2347fa0050a4ec630374899cb701 Mon Sep 17 00:00:00 2001 From: skye rogers Date: Thu, 27 Mar 2025 09:40:38 -0700 Subject: [PATCH] changed cvss check to < 0.1 for testing --- .github/workflows/maven.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/maven.yml b/.github/workflows/maven.yml index 908151df..eec362fa 100644 --- a/.github/workflows/maven.yml +++ b/.github/workflows/maven.yml @@ -26,7 +26,7 @@ jobs: github-token: "${{ secrets.GITHUB_TOKEN }}" - name: Enable auto-merge for Dependabot PRs # if: steps.metadata.outputs.update-type != 'version-update:semver-major' && cvss level > 0 - if: steps.metadata.outputs.update-type != 'version-update:semver-major' && steps.dependabot-metadata.outputs.cvss != 0 + if: steps.metadata.outputs.update-type != 'version-update:semver-major' && steps.dependabot-metadata.outputs.cvss < 0.1 run: gh pr merge --auto --merge "$PR_URL" env: PR_URL: ${{github.event.pull_request.html_url}}