unified-runtime
unified-runtime copied to clipboard
[Security] Dependabot/scorecard fixes and improvements
The dependabot.yml configuration is required by Scorecard. For now, PR adds a simple dependabot version and hashes update (open PR if new version is available). In the future, the configuration can be expanded to include other package-ecosystems.
This PR will fix a few of Pinned-Dependencies issues and Dependency-Update-Tool issue.