Skip to content

Disable dependabot and have bot update deps every week ? #2209

@PVince81

Description

@PVince81

Our working pattern so far in the last weeks was to ignore the huge list of dependabot PRs and rather do a single "update deps" pull request every week. This also aligns with our weekly (beta) releases.

I find the long list of dependabot PRs to be noisy and we could disable dependabot altogether, with the condition that we are able to setup a process that automatically updates all libs at once. It seems dependabot is not yet able to do that: https://github.com/dependabot/feedback/issues/5

The exception would be for security updates. Still, we have snyk already and Github warnings for security, in which cases we can also take care.

Thoughts ? @DeepDiver1975 @LukasHirt

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions