Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependa-duty #9920

Open
cdanfon opened this issue Jan 9, 2023 · 30 comments
Open

Dependa-duty #9920

cdanfon opened this issue Jan 9, 2023 · 30 comments
Assignees
Labels
engineering maintain Maintain digital systems

Comments

@cdanfon
Copy link

cdanfon commented Jan 9, 2023

[Timebox to 4 hours]

GOAL: Spend the timeboxed amount of time per sprint addressing Dependencies

Process for Github Dependabot Duty

Please use the process outlined in this document, Github: Dependabot Duty when you are assigned to this task.
Reach out to the team in Slack if you need access to the referenced document.

┆Issue is synchronized with this Jira Task

@cdanfon cdanfon added engineering maintain Maintain digital systems labels Jan 9, 2023
@mmmavis
Copy link
Collaborator

mmmavis commented Jan 23, 2023

At least half of the existing dependabot PRs have been closed! Hooray!

I created a new label "[dependabot] has breaking changes" to mark dependabot PRs containing breaking changes. Those PRs will require more time to fix, review and merge. Just a note that some remaining open PRs can still have breaking changes even though they don't have that label as I didn't have time to check through all PRs.

I'm hoping we can continue merging more dependabot PRs in the next few sprints to keep them at the manageable number. I don't mind taking on this task for the next sprint if other devs have other priorities. :)

@mmmavis
Copy link
Collaborator

mmmavis commented Jan 23, 2023

@cdanfon @mtdenton updates for the dependabot PRs merging progress is above. I'm unsure if this ticket is good to close so leaving the decision to you.

@mtdenton
Copy link
Collaborator

@mmmavis Thanks for this! We'll keep this open until we're caught up, you all can decide who will carry this forward in the next sprint.

@cdanfon cdanfon assigned danielfmiranda and unassigned mmmavis Jan 23, 2023
@cdanfon
Copy link
Author

cdanfon commented Feb 6, 2023

Hey @danielfmiranda can you give us an update as of where we are with dependabot issues? The above comment from Mavis is a perfect example :)

At least half of the existing dependabot PRs have been closed! Hooray!

I created a new label "[dependabot] has breaking changes" to mark dependabot PRs containing breaking changes. Those PRs will require more time to fix, review and merge. Just a note that some remaining open PRs can still have breaking changes even though they don't have that label as I didn't have time to check through all PRs.

I'm hoping we can continue merging more dependabot PRs in the next few sprints to keep them at the manageable number. I don't mind taking on this task for the next sprint if other devs have other priorities.

@danielfmiranda
Copy link
Collaborator

danielfmiranda commented Feb 21, 2023

Hi @cdanfon!

No problem, for my update:

  • Since we have had a code freeze going on for the wagtail 3.0 upgrade, I have not yet merged any dependabot PR's that I have taken a look at during the last sprint. I have only approved these PR's and left comments saying "OK to merge after code freeze". I plan to start merging these once the code freeze ends on 02/22/23
  • After taking a look at the zenhub board, it appears that there are 35 Dependabot PRs remaining for the foundation repo.

Thanks!

@cdanfon cdanfon assigned tbrlpld and unassigned fessehaye and tbrlpld Mar 6, 2023
@cdanfon
Copy link
Author

cdanfon commented Mar 6, 2023

We're skipping this duty during s/c 6th March

@tbrlpld
Copy link
Collaborator

tbrlpld commented Mar 8, 2023

For next round, we should focus on security critical updates: https://github.com/MozillaFoundation/foundation.mozilla.org/security/dependabot

@mmmavis mmmavis self-assigned this Mar 15, 2023
@cdanfon cdanfon assigned kevinhowbrook and unassigned mmmavis Mar 17, 2023
@tbrlpld tbrlpld changed the title Updating dependencies duty Depende duty Mar 17, 2023
@tbrlpld tbrlpld changed the title Depende duty Dependa duty Mar 17, 2023
@tbrlpld tbrlpld changed the title Dependa duty Dependa-duty Mar 17, 2023
@danielfmiranda
Copy link
Collaborator

Sprint 06/26/23 - 07/07/23:

@mtdenton
Copy link
Collaborator

mtdenton commented Aug 8, 2023

Pausing this for 8/7 sprint

@danielfmiranda danielfmiranda removed their assignment Sep 1, 2023
@jhonatan-lopes
Copy link
Contributor

jhonatan-lopes commented Oct 17, 2023

@jhonatan-lopes
Copy link
Contributor

jhonatan-lopes commented Nov 22, 2023

Sprint November 13th, 2023 - November 24th, 2023:

@jhonatan-lopes
Copy link
Contributor

jhonatan-lopes commented Dec 4, 2023

@jhonatan-lopes
Copy link
Contributor

jhonatan-lopes commented Dec 12, 2023

@jhonatan-lopes
Copy link
Contributor

jhonatan-lopes commented Jan 31, 2024

@data-sync-user
Copy link
Collaborator

➤ Mavis Ou commented:

Forgot to update this ticket last sprint. Below is what got merged.

Sprint March 4, 2024 - March 15, 2024

  1. Bump eslint from 8.49.0 to 8.57.0 #11902 ( https://github.com/MozillaFoundation/foundation.mozilla.org/pull/11902|smart-link )
  2. Bump @tailwindcss/forms from 0.5.6 to 0.5.7 #11416 ( https://github.com/MozillaFoundation/foundation.mozilla.org/pull/11416|smart-link )
  3. Bump classnames from 2.3.2 to 2.5.1 #11624 ( https://github.com/MozillaFoundation/foundation.mozilla.org/pull/11624|smart-link )
  4. Bump classnames from 2.3.2 to 2.5.1 #11624 ( https://github.com/MozillaFoundation/foundation.mozilla.org/pull/11624|smart-link )
  5. Bump countup.js from 2.7.0 to 2.8.0 #11036 ( https://github.com/MozillaFoundation/foundation.mozilla.org/pull/11036|smart-link )
  6. Bump browserslist from 4.21.10 to 4.23.0 #11881 ( https://github.com/MozillaFoundation/foundation.mozilla.org/pull/11881|smart-link )
  7. Bump autoprefixer from 10.4.15 to 10.4.18 #11969 ( https://github.com/MozillaFoundation/foundation.mozilla.org/pull/11969|smart-link )
  8. Bump postcss-scss from 4.0.6 to 4.0.9 #11199 ( https://github.com/MozillaFoundation/foundation.mozilla.org/pull/11199|smart-link )
  9. Bump eslint-plugin-react from 7.32.2 to 7.34.0 #12015 ( https://github.com/MozillaFoundation/foundation.mozilla.org/pull/12015|smart-link )
  10. Bump postcss from 8.4.33 to 8.4.35 #11859 ( https://github.com/MozillaFoundation/foundation.mozilla.org/pull/11859|smart-link )
  11. Bump sentry-sdk from 1.40.1 to 1.41.0 #12029 ( https://github.com/MozillaFoundation/foundation.mozilla.org/pull/12029|smart-link )
  12. Bump cssnano from 6.0.1 to 6.1.0 #12016 ( https://github.com/MozillaFoundation/foundation.mozilla.org/pull/12016|smart-link )
  13. Bump tailwindcss from 3.3.3 to 3.4.1 #11662 ( https://github.com/MozillaFoundation/foundation.mozilla.org/pull/11662|smart-link )
  14. Bump @playwright/test from 1.36.1 to 1.42.1 #11971 ( https://github.com/MozillaFoundation/foundation.mozilla.org/pull/11971|smart-link )
  15. Bump follow-redirects from 1.15.5 to 1.15.6 #12054 ( https://github.com/MozillaFoundation/foundation.mozilla.org/pull/12054|smart-link )
  16. Bump the npm_and_yarn group group with 1 update #12059 ( https://github.com/MozillaFoundation/foundation.mozilla.org/pull/12059|smart-link )
  17. Bump browser-sync from 2.29.3 to 3.0.2 #11627 ( https://github.com/MozillaFoundation/foundation.mozilla.org/pull/11627|smart-link )
  18. Bump postcss-cli from 10.1.0 to 11.0.0 #11523 ( https://github.com/MozillaFoundation/foundation.mozilla.org/pull/11523|smart-link )

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
engineering maintain Maintain digital systems
Projects
None yet
Development

No branches or pull requests

10 participants