From 67673ff6d7e4271aeb684b01a56dbc79ef553d1a Mon Sep 17 00:00:00 2001 From: games647 Date: Wed, 19 May 2021 17:46:59 +0200 Subject: [PATCH] Ignore log4j in dependency updates --- .github/dependabot.yml | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index e8d23a6..61ef411 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -5,6 +5,5 @@ updates: schedule: interval: weekly ignore: + # Ignore log4j, because it's a provided library - dependency-name: org.apache.logging.log4j:log4j-core - versions: - - 2.13.2