-
Notifications
You must be signed in to change notification settings - Fork 0
Ticket Template: Enabling dependabot
Maria Fisher edited this page Jan 7, 2026
·
9 revisions
## Description
Add dependabot package updater to this repository. For more info, see https://library.thinkshoutlabs.com/articles/dependabot
## Timeline
Non-urgent, can be grouped with next quarterly update or maintenance work.
## Hours expected to complete
1-3
## Dev Notes
Here are some example PRs for this work:
Wordpress example: https://github.com/thinkshout/tror/pull/2388/files
Drupal example that already had drupal-integrations: https://github.com/thinkshout/calc/pull/1723/files
Drupal example that did not have drupal-integrations: https://github.com/thinkshout/demos/pull/771
## Dev tasks
### Enable Security alerts
- [ ] At https://github.com/thinkshout/YOURSITE/settings/security_analysis turn on "Dependabot security updates" if it isn't already enabled.
### Pull in https://github.com/thinkshout/drupal-integrations.
- [ ] If your site is Drupal and already has the `thinkshout/drupal-integrations` package, just run `composer update thinkshout/drupal-integrations`
- [ ] If your site is Drupal and does not already have the `thinkshout/drupal-integrations` package, follow the instructions under "Enabing This Project" https://github.com/thinkshout/drupal-integrations?tab=readme-ov-file#enabling-this-project
- [ ] If your site is a Wordpress site, you can pull in the files you need with these commands:
`composer require --dev thinkshout/drupal-integrations:^3.0`
`cp -r vendor/thinkshout/drupal-integrations/assets/.github/* .github`
`composer remove thinkshout/drupal-integrations`
You can also just manually copy and paste the three files from [this repo's assets directory](https://github.com/thinkshout/drupal-integrations/tree/main/assets/.github), if composer is not installed or is being annoying.
### Customize your files.
- [ ] In your repo's `.github/CODEOWNERS` file, add your username, if you are the person most likely to review or push code. Example: `* @mariacha` (note that's * then TAB then @thename)
- [ ] In your repo's `.github/dependabot.yml` file, add an entry for every folder containing a `package.json` file that we actively manage. Usually this is just a single theme, but some sites have react apps or multiple themes.
- [ ] Make sure your `.github/workflows/dependabot-comment.yml` is not being gitignored via a file at `.github/workflows/.gitignore`
- [ ] Assign PRs to Maria, or merge them yourself if you feel confident about it!
If you run into any trouble, @mariacha in the ticket or via slack, or watch [the dev team video about this found here](https://drive.google.com/drive/folders/1_Hf-jVqnLFq05xEXnj7gTgwwHIiVYRET)
## This ticket is done when:
- [ ] The three files noted above are committed to your repo.
- [ ] Dependabot is running.