Skip to content
This repository was archived by the owner on Nov 10, 2025. It is now read-only.

Schedule dependabot updates every Sunday#756

Merged
jamie-o-wilkinson merged 1 commit intomainfrom
update-dependabot-config
May 16, 2025
Merged

Schedule dependabot updates every Sunday#756
jamie-o-wilkinson merged 1 commit intomainfrom
update-dependabot-config

Conversation

@jamie-o-wilkinson
Copy link
Copy Markdown
Contributor

What problem does this pull request solve?

Dependabot updates are getting burdensome. Dependabot docs recommend scheduling updates to reduce this workload somewhat. The goal here is that the week's dependabot PRs would all be raised at the beginning of the working week, giving us time to sort them out before more get raised the following week. Security updates should still get raised along with associated security alerts.

In future we could also use groups to e.g. gather all dev dependencies into a single PR.

Things to consider when reviewing

  • Ensure that you consider the wider context.
  • Does it work when run on your machine?
  • Is it clear what the code is doing?
  • Do the commit messages explain why the changes were made?
  • Are there all the unit tests needed?
  • Has all relevant documentation been updated?

@jamie-o-wilkinson jamie-o-wilkinson self-assigned this May 16, 2025
Copy link
Copy Markdown
Contributor

@DavidBiddle DavidBiddle left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved! rebasing should solve the security audit failure

@jamie-o-wilkinson jamie-o-wilkinson force-pushed the update-dependabot-config branch from bcaf69b to 7bacc6c Compare May 16, 2025 15:15
Dependabot updates are getting burdensome. Dependabot docs recommend
scheduling updates to reduce this workload somewhat. The goal here is
that the week's dependabot PRs would all be raised at the beginning of
the working week, giving us time to sort them out before more get
raised the following week. Security updates should still get raised
along with associated security alerts.

In future we could also use groups to e.g. gather all dev dependencies
into a single PR.
@jamie-o-wilkinson jamie-o-wilkinson force-pushed the update-dependabot-config branch from 7bacc6c to c6a9ebb Compare May 16, 2025 15:43
@sonarqubecloud
Copy link
Copy Markdown

@jamie-o-wilkinson jamie-o-wilkinson merged commit aa6bdd5 into main May 16, 2025
4 checks passed
@jamie-o-wilkinson jamie-o-wilkinson deleted the update-dependabot-config branch May 16, 2025 15:44
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants