Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ci: add dependabot package updating #202

Closed
wants to merge 1 commit into from
Closed

Conversation

robjtede
Copy link
Member

@robjtede robjtede commented Aug 14, 2023

partly so that we have PRs to merge to resolve the stuck issues faster

this config set up is pretty good for application projects in my experience

partly so that we have PRs to merge to resolve the stuck issues faster
@paolobarbolini
Copy link
Member

I think it's a good idea in general to automate dependency updates. Considering that dependabot ignores the interval setting when it comes to security updates 1, I wouldn't run this daily.

partly so that we have PRs to merge to resolve the stuck issues faster

Actually we haven't automated deployments to the server, so merging a PR doesn't fix the stuck issues 😅

Footnotes

  1. https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#scheduleinterval

@robjtede robjtede closed this Aug 20, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants