Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

enable Dependabot v2 #5077

Merged
merged 1 commit into from
Aug 15, 2020
Merged

enable Dependabot v2 #5077

merged 1 commit into from
Aug 15, 2020

Conversation

sullis
Copy link
Contributor

@sullis sullis commented Jul 24, 2020

Signed-off-by: Sean C. Sullivan <github@seansullivan.com>
@joakime
Copy link
Contributor

joakime commented Jul 24, 2020

Dependabot warnings and notices are already enabled for this project.

However, due to legal reasons, we do not support the features of dependabot that automatically updates the dependencies in the project.

@janbartel
Copy link
Contributor

@joakime is there a change that @sullis can make that would make this PR acceptable?

@joakime
Copy link
Contributor

joakime commented Aug 11, 2020

He could explain what this does, and what he hopes for the project.

We already have the dependabot warnings and notices enabled for this project for incoming changes.
We also have the dependabot external notifications setup to allow other projects to benefit from our changes in their dependabot enabled projects.
(example: jetty-project/jetty-maven-wagon#8)

If this PR is meant to automatically upgrade our dependencies, that we cannot support due to Eclipse Legal and lack of ECA in that process.

I'll give the OP 24 hours to reply, if I don't get anything i'm closing this PR.

@olamy
Copy link
Member

olamy commented Aug 12, 2020

we will get a lot of (noisy?) pr to update our external dependencies such maven plugins, librairies(mongo, hazelcast)
I'm ok to give a try but do we really want to use every last version for everything? I'm happy to be compatible with old versions of infinispan, mongo etc...
thoughts?

@olamy
Copy link
Member

olamy commented Aug 15, 2020

@joakime this doesn't update automatically the project but create PR so we can look if it need some Eclipse IP request.

@olamy olamy merged commit 74a1638 into jetty:jetty-10.0.x Aug 15, 2020
@gregw
Copy link
Contributor

gregw commented Aug 18, 2020

@olamy the generated PRs are not building and they are targeting 10, when 9 with merge forward would be better.

Could we just change this to a weekly or monthly report?

@olamy
Copy link
Member

olamy commented Aug 18, 2020

@gregw already changed to weekly 084db19
as far I understand the tool can work only on the main branch dependabot/dependabot-core#2159 maybe it's possible with using the UI (but I don't have the access to setup this in this project and not sure how to do it)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants