Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Removal of dependabot #380

Closed
djaiss opened this issue Nov 5, 2020 · 2 comments
Closed

Removal of dependabot #380

djaiss opened this issue Nov 5, 2020 · 2 comments

Comments

@djaiss
Copy link
Member

djaiss commented Nov 5, 2020

Dependabot creates a lot of noise in the commit logs.

Could we, instead, schedule a github action that would do a composer update and yarn every week, and commit this with a simple commit message, instead of 12 commits? @asbiin what do you think?

@asbiin
Copy link
Contributor

asbiin commented Dec 8, 2020

I don't think that's recommended neither feasible.
Changing dependencies can lead to test fails, and diagnosis of fails would be very hard if multiple upgrade are mixed in a same commit/PR.
Example with these PR:

I understand you see that as "noise", but on the other hand it guarantee the stability of the product. (you just have to made more commits yourself!)

@djaiss djaiss closed this as completed Jan 5, 2021
@github-actions
Copy link
Contributor

github-actions bot commented Jan 6, 2022

This issue has been automatically locked since there
has not been any recent activity after it was closed.
Please open a new issue for related bugs.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Jan 6, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants