ci(dependencies): add dependabot config#2311
Closed
ReenigneArcher wants to merge 1 commit intodevicons:developfrom
Closed
ci(dependencies): add dependabot config#2311ReenigneArcher wants to merge 1 commit intodevicons:developfrom
ReenigneArcher wants to merge 1 commit intodevicons:developfrom
Conversation
24f72c5 to
569e99b
Compare
Collaborator
|
Dependabot is nice to have, but I don't think we should merge this before we get trunk based branching. As it is now it's too much hassle to check if updated dependencies work as expected, and we don't have proper automated tests in order to confidently merge without manually testing. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Double check these details before you open a PR
Features
This PR adds a dependabot configuration to automatically update dependencies. It will automatically create PRs for outdated dependencies of the following types.
requirements*.txtfiles even in subfolders, but I don't know if will work in the.githubdirectory)This PR closes NONE
Notes
This will not start working until the file exists on the default branch. Additionally, dependabot will only run the config that exists on the default branch. This is one reason I would suggest making the default branch
develop, although there are plenty of other reasons which mostly involve improving the developer experience.Personally, I set my dependabot config to run daily, but that may be too overwhelming/annoying for this repo, so I changed it to weekly.
For more dependabot config options, here is the official documentation: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file