-
Notifications
You must be signed in to change notification settings - Fork 2.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Disable dependabot and add process for updating all deps after each release #1659
Comments
I do what is it that is keeping us from merging these PRs? It seems like continuously doing this is a better idea then at once. Do we not have the confidence? Is it too much? Generally speaking this still seems like a good idea in theory, I want to understand what's making it not useful in practice (and/or if we could make it useful 🙂 ). |
Sure, so problems with current approach:
|
It's probably worth giving the dependabot folks this feedback. I'd say let's make it release shepherd responsibility, that seems like a reasonable thing (of course one off bumps are not discouraged). |
Ticket sent, no response |
5 days later, did you get a response in the meantime? |
Nope: It is also Github support as it was acquired. No response at all ):
…On Mon, 28 Oct 2019 at 11:06, Matthias Loibl ***@***.***> wrote:
5 days later, did you get a response in the meantime?
—
You are receiving this because you authored the thread.
Reply to this email directly, view it on GitHub
<#1659?email_source=notifications&email_token=ABVA3OYPQQ6RLP6U7WV2OF3QQ3BT7A5CNFSM4JBXYBW2YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOECMP6SY#issuecomment-546897739>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/ABVA3OYEIML3WMWES5V72X3QQ3BT7ANCNFSM4JBXYBWQ>
.
|
Actually forget about a support ticket, look at this: https://github.com/dependabot/feedback/issues/5 👀 Will describe our use case and will check if we can help in any way. |
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions. |
We are kind of behind dependencies and being spammed by
It would be nice to configure dependabot to do all in one PR. I can't see such an option so I have created a support ticket.
Should it be a release shepherd responsibility?
AC:
cc @brancz @domgreen @GiedriusS @metalmatze @adrien-f @FUSAKLA opinions?
The text was updated successfully, but these errors were encountered: