Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: Tweak dependabot #223

Merged
merged 1 commit into from
Oct 10, 2024
Merged

chore: Tweak dependabot #223

merged 1 commit into from
Oct 10, 2024

Conversation

jmgate
Copy link
Collaborator

@jmgate jmgate commented Oct 10, 2024

Type: Task

Description

Run weekly instead of daily, and group updates into a single PR for each packaging ecosystem.

Motivation

Just tired of so many dependency updates. Our existing configuration was automatically generated by the @step-security-bot, following best practices defined by the OpenSSF, but I'm not convinced updating all dependencies on a potentially daily basis via separate PRs is the best thing to do.

Implementation Details

Followed this documentation.

Run weekly instead of daily, and group updates into a single PR for each
packaging ecosystem.
@jmgate jmgate self-assigned this Oct 10, 2024
Copy link

codecov bot commented Oct 10, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 94.04%. Comparing base (48e71aa) to head (c4c9252).
Report is 2 commits behind head on master.

Additional details and impacted files
@@           Coverage Diff           @@
##           master     #223   +/-   ##
=======================================
  Coverage   94.04%   94.04%           
=======================================
  Files           2        2           
  Lines         168      168           
  Branches       42       42           
=======================================
  Hits          158      158           
  Misses          4        4           
  Partials        6        6           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@jmgate jmgate merged commit e5fcb10 into master Oct 10, 2024
14 checks passed
@jmgate jmgate deleted the tweak-dependabot branch October 10, 2024 14:22
@GhostofGoes
Copy link
Collaborator

THANK YOU. I was close to muting notifications from this repo because dependabot made up half of my notifications for a week 😅

@jmgate
Copy link
Collaborator Author

jmgate commented Oct 10, 2024

Yeah, I don't know why the official recommendations are so noisy. I'll make sure dependabot still runs correctly when next it kicks off, and then I'll make the same changes to my other repositories as well.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants