Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump boto3 from 1.12.27 to 1.12.28 #26

Closed
wants to merge 1 commit into from

Conversation

dependabot-preview[bot]
Copy link
Contributor

@dependabot-preview dependabot-preview bot commented Mar 25, 2020

Bumps boto3 from 1.12.27 to 1.12.28.

Changelog

Sourced from boto3's changelog.

1.12.28

  • api-change:athena: [botocore] Update athena client to latest version
  • api-change:rds-data: [botocore] Update rds-data client to latest version
  • api-change:eks: [botocore] Update eks client to latest version
  • api-change:organizations: [botocore] Update organizations client to latest version
Commits
  • a8032a2 Merge branch 'release-1.12.28'
  • 7b5fb70 Bumping version to 1.12.28
  • 1690afb Add changelog entries from botocore
  • bb1b791 Merge branch 'release-1.12.27' into develop
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

Bumps [boto3](https://github.com/boto/boto3) from 1.12.27 to 1.12.28.
- [Release notes](https://github.com/boto/boto3/releases)
- [Changelog](https://github.com/boto/boto3/blob/develop/CHANGELOG.rst)
- [Commits](boto/boto3@1.12.27...1.12.28)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview bot added the dependencies Pull requests that update a dependency file label Mar 25, 2020
@negillett
Copy link
Member

@rohanpm anyway to configure the bot to only bump for y-streams?

@rohanpm
Copy link
Member

rohanpm commented Mar 25, 2020

@rohanpm anyway to configure the bot to only bump for y-streams?

I'll look into it... I'm also a bit surprised how many of these we're getting. Dependabot settings in the repo are meant to apply security fixes only by default, but I suspect it might not be working correctly or maybe every release of this library is being marked as "contains security fixes".

@rohanpm
Copy link
Member

rohanpm commented Mar 26, 2020

I have a feeling that the dependabot config file I checked into the repo was not respected. Others have hit the same issue before, e.g. dependabot/feedback#857. I checked repo settings in the dependabot app and it didn't have "security updates only" as it should according to the config file.

I manually adjusted the settings to match the config file. We could merge the outstanding requests and then see if the behavior changes to expected from now (= only security updates). @nathanegillett what do you think?

@dependabot-preview
Copy link
Contributor Author

Looks like boto3 is up-to-date now, so this is no longer needed.

@dependabot-preview dependabot-preview bot deleted the dependabot/pip/boto3-1.12.28 branch March 26, 2020 00:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants