Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FR]: Document the dependency update process #1083

Open
2 tasks done
SimonMarquis opened this issue Dec 8, 2023 · 0 comments
Open
2 tasks done

[FR]: Document the dependency update process #1083

SimonMarquis opened this issue Dec 8, 2023 · 0 comments
Labels
enhancement New feature or request

Comments

@SimonMarquis
Copy link
Contributor

Is there an existing issue for this?

  • I have searched the existing issues

Describe the problem

Now that we have enabled first party support for dependency updates #893, we should also go the extra mile to ensure a smooth and timely update process.

Pending dependabot updates are listed here:

Describe the solution

  1. Duplicating reviews and pinging maintainers is probably not a good solution...

  2. The simpler solution would be to give review/write permission to more maintainers, but I understand that this could be difficult to set up, with legal concerns.

  3. An alternative could be to implement an automated update process to approve and merge patch/minor updates when the build succeeds. This can be implemented with a custom workflow like this one (as documented here).

Additional context

We might also document the chosen solution (process, implications, etc.) in the main README.md for everyone to read.

Code of Conduct

  • I agree to follow this project's Code of Conduct
@SimonMarquis SimonMarquis added the enhancement New feature or request label Dec 8, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant