Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Migrate to native dependabot #657

Merged
merged 1 commit into from Feb 6, 2021
Merged

Conversation

lcobucci
Copy link
Owner

@lcobucci lcobucci commented Feb 6, 2021

No description provided.

@lcobucci lcobucci added the CI label Feb 6, 2021
@lcobucci lcobucci added this to the 4.2.0 milestone Feb 6, 2021
@lcobucci lcobucci self-assigned this Feb 6, 2021
@lcobucci lcobucci merged commit e8fdb22 into 4.2.x Feb 6, 2021
@lcobucci lcobucci deleted the migrate-to-native-dependabot branch February 6, 2021 21:47
versioning-strategy: increase
open-pull-requests-limit: 20
allow:
- dependency-type: all
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

May I ask you if this is really necessary?
I fear that so many notifications just end up being trashed by everyone, even the ones that may have value been reviewed supervisioned.
What about direct only?

DOC: https://docs.github.com/en/github/administering-a-repository/configuration-options-for-dependency-updates#allow

Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I want for all dependencies to be as up-to-date as possible. There's tooling to auto-merge everything that passes CI so there's very little tracking to be done.

I do understand the concern around the volume of notifications there's also rate limiting happening sometimes... the trade-offs in play here is to ensure that development of the library works in the same way for everybody and that nobody has to update dependencies manually.

I'd love if dependabot would run things with composer require x -W to update the dependencies of our dependencies together with the changes being introduced but that's not the case now 😞

Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(I do hate when symfony update their packages without releasing anything, though)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants