Conversation
Code ReviewI've reviewed the Dependabot configuration. This looks good overall - all the ignored dependencies have corresponding comments in Configuration AnalysisThe ignored dependencies align with the TODO comments and pinning notes in
Minor Suggestions (non-blocking)
The PR author's concern about "many exceptions" is understandable, but each one is justified by technical constraints documented in the codebase. This is a pragmatic approach for maintaining dependency hygiene while respecting the project's technical constraints. ✅ Approved - No critical issues. The configuration is safe and aligns with documented dependency constraints. |
It took me some time to learn, but the PR title should be: |
|
Haha done it before I saw the message :) |
DSharifi
left a comment
There was a problem hiding this comment.
can you run the action manually once so we can see it works before merging?
Closes #2016
I find it a little concerning that I had to add this many exceptions in upgrades.