Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot pull-requests #344

Closed
github-actions bot opened this issue Dec 1, 2024 · 1 comment
Closed

Dependabot pull-requests #344

github-actions bot opened this issue Dec 1, 2024 · 1 comment

Comments

@github-actions
Copy link

github-actions bot commented Dec 1, 2024

This is an automatically created issue used to list dependabot pull requests every 3 months.

It was created by the .github/workflows/dependabot-prs-issue.yml workflow in the silverstripe/.github repository.

Triage instructions (Silverstripe Ltd CMS Squad)

  1. Put on the following labels:
    • type/bug
    • impact/low
  2. Move this issue to the "Ready" column on our internal zenhub board
  3. If there is an open issue for JS PRs, block this issue on it - those PRs may resolve some dependabot alerts

Dependabot pull-requests:

See the list of dependabot pull-requests in Rhino.

  • Make a quick determination as to whether the vulnerability fixed by the PR warrants using our security process
    • You can check to see if the dependabot alert affects non-dev dependencies by running yarn audit --groups dependencies locally on default branch of the module.
    • Use yarn audit --groups devDependencies to see dev-only dependencies.
  • Merge these PRs if there are no merge-conflicts and CI is green
  • If there are conflicts or CI isn't green, get dependabot to recreate the PR
  • If there are still problems, manually resolve them and open your own PR
  • Backport anything that seems like it needs to be patched immediately

Dependabot alerts:

After all of the above have been completed and resolved, check for any outstanding dependabot alerts in the list below.

  • Make a quick determination as to whether any alerts warrant using our security process
  • Ignore or dismiss any alerts that aren't relevant
  • Try to resolve any relevant alerts which dependabot is unable to resolve automatically

Respositories with alerts:

PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants