-
Notifications
You must be signed in to change notification settings - Fork 218
ci(dep): update dependabot configuration #2338
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ci(dep): update dependabot configuration #2338
Conversation
This commit updates the existing dependabot configuration: Changes include: * Explicitly set PR limits to 5 * Add labels - All PRs will be tagged with: * `dependencies` (common label) * Ecosystem label (go, github-actions) Signed-off-by: vprashar2929 <[email protected]>
2adff1e to
8984ab4
Compare
| update-types: [version-update:semver-major, version-update:semver-minor] | ||
| commit-message: | ||
| include: scope | ||
| open-pull-requests-limit: 5 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
do we need limit PR number to 5?
in an edge case, we meet this limitation and a new cve happens in one of our dependency.
a new patch is ready on upstream, can we benefits from https://github.com/sustainable-computing-io/kepler/security/dependabot to open a new PR as #2247 for now, over the limitation, having the 6 PRs and patched?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Lets start with 5 (since the PR is already mergable). If in future, we have to raise the number, we can deal with it then.
SamYuan1990
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM, leave comments.
| update-types: [version-update:semver-major, version-update:semver-minor] | ||
| commit-message: | ||
| include: scope | ||
| open-pull-requests-limit: 5 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Lets start with 5 (since the PR is already mergable). If in future, we have to raise the number, we can deal with it then.
This commit updates the existing dependabot configuration:
Changes include:
dependencies(common label)