Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(workflow): remove dependabot workflow #5261

Closed
wants to merge 4 commits into from
Closed

chore(workflow): remove dependabot workflow #5261

wants to merge 4 commits into from

Conversation

AugustinMauroy
Copy link
Member

No description provided.

@AugustinMauroy AugustinMauroy requested a review from a team as a code owner April 12, 2023 12:19
Copy link
Member

@ovflowd ovflowd left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! Let's remove Dependabot for now.

Copy link
Contributor

@SEWeiTung SEWeiTung left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LTGM!

SEWeiTung
SEWeiTung previously approved these changes Apr 13, 2023
Copy link
Member

@mikeesto mikeesto left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For context: I think the reason we are temporarily disabling Dependabot is because of the significant migration work happening on the /major/website-redesign branch, and trying to reduce the likelihood of dependency conflicts when it lands. A decrease in notifications within our GitHub inboxes is an added bonus too...

@ovflowd
Copy link
Member

ovflowd commented Apr 13, 2023

@MaledongGit dependabot alerts are about the security alerts feature. Not the PRs for dependency updatee.

@SEWeiTung
Copy link
Contributor

SEWeiTung commented Apr 14, 2023

@MaledongGit dependabot alerts are about the security alerts feature. Not the PRs for dependency updatee.

@ovflowd

I submitted a PR to make a feature request to the dependabot, however the author of GitHub's waiting for my response, and I don't have the authentication to verify whether it works? Can any of you check it? I was told not only security alerts but updates as well……

Refs:dependabot/dependabot-core#7072

If this still doesn't work, I'll submit and give him a reason why, otherwises I'll close this feature.

@ovflowd
Copy link
Member

ovflowd commented Apr 14, 2023

@MaledongGit dependabot security alerts are an entirely different feature from dependabot automatic dependency updates, as I mentioned before.

Edit: It seems that we're able indeed to disable it via options, but I'm unable to find that option. Will give it another try.

Copy link
Member

@ovflowd ovflowd left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still waiting for the unrelated changes to be undone 👀 (referring to remove the github-actions config for dependabot)

@SEWeiTung
Copy link
Contributor

@MaledongGit dependabot security alerts are an entirely different feature from dependabot automatic dependency updates, as I mentioned before.

Edit: It seems that we're able indeed to disable it via options, but I'm unable to find that option. Will give it another try.

Yes, It would be better if we can keep the file :)

@SEWeiTung SEWeiTung dismissed their stale review April 15, 2023 04:28

Waiting for response of a better solution

@ovflowd
Copy link
Member

ovflowd commented Apr 15, 2023

I'm closing this PR as there's a few controversial things happening at play. I'll reach out GitHub support.

@ovflowd ovflowd closed this Apr 15, 2023
@AugustinMauroy AugustinMauroy deleted the remove branch April 15, 2023 07:51
@SEWeiTung
Copy link
Contributor

Just a tip only (no need to change any more but just let you what to do if we meet such problems):

https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuring-dependabot-version-updates#disabling-dependabot-version-updates

Just a very simple sample XD XD XD

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants