Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create Dependabot config file #374

Merged
merged 5 commits into from
Jul 3, 2021
Merged

Conversation

dependabot-preview[bot]
Copy link
Contributor

👋 Dependabot is moving natively into GitHub! This pull request migrates your configuration from Dependabot.com to a config file, using the new syntax. When you merge this pull request, we'll swap out dependabot-preview (me) for a new dependabot app, and you'll be all set!

With this change, you'll now use the Dependabot page in GitHub, rather than the Dependabot dashboard, to monitor your version updates. Dependabot is now configured exclusively using config files.

If you've got any questions or feedback for us, please let us know by creating an issue in the dependabot/dependabot-core repository.

Learn more about the relaunch of Dependabot

Please note that regular @dependabot commands do not work on this pull request.

🤖💛

@dependabot-preview dependabot-preview bot added the dependencies Pull requests that update a dependency file label Aug 28, 2020
@dschaper dschaper marked this pull request as draft August 28, 2020 18:53
@dschaper
Copy link
Member

This was autogenerated, we need to review it and adjust accordingly.

@netlify
Copy link

netlify bot commented Oct 2, 2020

✔️ Deploy Preview for pihole-docs ready!

🔨 Explore the source changes: fe92473

🔍 Inspect the deploy log: https://app.netlify.com/sites/pihole-docs/deploys/60e0cc6814656a00088f93a4

😎 Browse the preview: https://deploy-preview-374--pihole-docs.netlify.app

@XhmikosR
Copy link
Contributor

Does anybody recall why tornado was excluded? I don't think we even have this dependency anymore.

The rest of the changes look good, they are just backported.

@dschaper
Copy link
Member

The template was auto-generated. None of the contents are opinionated or chosen/excluded for any known reason.

It's just what the bot wrote.

@dschaper dschaper marked this pull request as ready for review October 15, 2020 02:14
@XhmikosR
Copy link
Contributor

It's not what the bot wrote; everything is migrated from the current config

dependabot-preview bot and others added 2 commits October 15, 2020 07:12
@XhmikosR XhmikosR force-pushed the dependabot/add-v2-config-file branch from 246ff8d to 479b218 Compare October 15, 2020 04:14
@dschaper
Copy link
Member

It's not what the bot wrote; everything is migrated from the current config

It's a PR literally opened by the bot itself.

@XhmikosR
Copy link
Contributor

Yeah, but it just migrated the current config.

@dschaper
Copy link
Member

Then I have no reason why tornado was excluded.

@XhmikosR
Copy link
Contributor

Must have been an old thing, but since we now include the top-level deps, it's moot. I think we can merge this :)

XhmikosR
XhmikosR previously approved these changes Oct 15, 2020
@XhmikosR
Copy link
Contributor

The only thing we need to consider is that automerging does not currently work: dependabot/dependabot-core#1973

@dschaper
Copy link
Member

Thanks for finding that. I think the dependabot/dependabot-core#1973 (comment) solution is feasible.

@XhmikosR
Copy link
Contributor

For security reasons, I would suggest that we stick with the current solution and block this PR until there's a proper solution in core.

@DL6ER
Copy link
Member

DL6ER commented Jan 9, 2021

@DL6ER DL6ER added the blocked label Jan 9, 2021
@dschaper
Copy link
Member

How about using

SGTM.

@XhmikosR
Copy link
Contributor

I believe GitHub now has some kind of auto-merge feature, not sure how good it works with dependabot, though. But this is the only way forward, although we might need to wait for the needed functionality from GitHub.

@dependabot-preview
Copy link
Contributor Author

As a reminder, Dependabot Preview will be shut down on August 3rd, 2021. You can merge this pull request to migrate to GitHub-native Dependabot. You can read the docs to learn more about what's changing, as well as find out how to get support if you need help migrating.

@PromoFaux
Copy link
Member

Hold my beer.. we're going github native (we won't have any choice in a month anyway)

@PromoFaux PromoFaux merged commit e0a9973 into master Jul 3, 2021
@PromoFaux PromoFaux deleted the dependabot/add-v2-config-file branch July 3, 2021 20:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants