Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot vs Renovate #703

Closed
jlosito opened this issue Feb 14, 2021 · 3 comments
Closed

Dependabot vs Renovate #703

jlosito opened this issue Feb 14, 2021 · 3 comments
Labels
Provider Status: Stale Used by stalebot to clean house Type: Feature New feature or request

Comments

@jlosito
Copy link
Contributor

jlosito commented Feb 14, 2021

Hi there,

Thank you for opening an issue. Please note that we try to keep the Terraform issue tracker reserved for bug reports and feature requests. For general usage questions, please see: https://www.terraform.io/community.html.

Behavior

What happened?

It appears that this project is using both renovate and dependabot at the same time. Personally I'm impartial to either tool. I believe one tool should probably be chosen whether that be dependabot or renovate and the other should be removed from the project so that there's a single point of truth as to which packages should be upgraded.

I'm not too sure if there's any benefit having both tools. Maybe there is. From my understanding, these are competing tools and essentially try to achieve the same goal. My concern is that one config is stating to ignore some dependencies, the other is not ignoring those dependencies. Furthermore, I'm not entirely sure if renovate is able to track upgrading GitHub action packages or if it only includes go modules.

@jcudit
Copy link
Contributor

jcudit commented Feb 26, 2021

Thanks for pointing this out. From a maintenance point of view, dependabot is more verbose, which helps to keep dependency upgrades visible. My preference here is to remove renovate, but am open to other opinions. I have not noticed any friction as yet within the community around this, so admittedly would not seek to address it ahead of other tasks.

@jcudit jcudit added Type: Feature New feature or request Provider labels Feb 26, 2021
@github-actions
Copy link

github-actions bot commented Dec 4, 2022

👋 Hey Friends, this issue has been automatically marked as stale because it has no recent activity. It will be closed if no further activity occurs. Please add the Status: Pinned label if you feel that this issue needs to remain open/active. Thank you for your contributions and help in keeping things tidy!

@github-actions github-actions bot added the Status: Stale Used by stalebot to clean house label Dec 4, 2022
@kfcampbell
Copy link
Member

In #1394 I removed Renovate from the project so we're officially using Dependabot here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Provider Status: Stale Used by stalebot to clean house Type: Feature New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants