Skip to content

Ticket Template: Enabling dependabot

Maria Fisher edited this page Jan 7, 2026 · 9 revisions
## Description
Add dependabot package updater to this repository. For more info, see https://library.thinkshoutlabs.com/articles/dependabot

## Timeline
Non-urgent, can be grouped with next quarterly update or maintenance work.

## Hours expected to complete
1-3

## Dev Notes
Here are some example PRs for this work:
Wordpress example: https://github.com/thinkshout/tror/pull/2388/files
Drupal example that already had drupal-integrations: https://github.com/thinkshout/calc/pull/1723/files
Drupal example that did not have drupal-integrations: https://github.com/thinkshout/demos/pull/771

## Dev tasks 
### Enable Security alerts
- [ ] At https://github.com/thinkshout/YOURSITE/settings/security_analysis turn on "Dependabot security updates" if it isn't already enabled.

### Pull in https://github.com/thinkshout/drupal-integrations.
  - [ ] If your site is Drupal and already has the `thinkshout/drupal-integrations` package, just run `composer update thinkshout/drupal-integrations`
  - [ ] If your site is Drupal and does not already have the `thinkshout/drupal-integrations` package, follow the instructions under "Enabing This Project" https://github.com/thinkshout/drupal-integrations?tab=readme-ov-file#enabling-this-project
  - [ ] If your site is a Wordpress site, you can pull in the files you need with these commands:

`composer require --dev thinkshout/drupal-integrations:^3.0`
`cp -r vendor/thinkshout/drupal-integrations/assets/.github/* .github`
`composer remove thinkshout/drupal-integrations`

You can also just manually copy and paste the three files from [this repo's assets directory](https://github.com/thinkshout/drupal-integrations/tree/main/assets/.github), if composer is not installed or is being annoying.

### Customize your files.
- [ ] In your repo's `.github/CODEOWNERS` file, add your username, if you are the person most likely to review or push code. Example: `*    @mariacha` (note that's * then TAB then @thename)
- [ ] In your repo's `.github/dependabot.yml` file, add an entry for every folder containing a `package.json` file that we actively manage. Usually this is just a single theme, but some sites have react apps or multiple themes.
- [ ] Make sure your `.github/workflows/dependabot-comment.yml` is not being gitignored via a file at `.github/workflows/.gitignore`
- [ ] Assign PRs to Maria, or merge them yourself if you feel confident about it!

If you run into any trouble, @mariacha in the ticket or via slack, or watch [the dev team video about this found here](https://drive.google.com/drive/folders/1_Hf-jVqnLFq05xEXnj7gTgwwHIiVYRET)

## This ticket is done when:
- [ ] The three files noted above are committed to your repo.
- [ ] Dependabot is running.

Clone this wiki locally