-
-
Notifications
You must be signed in to change notification settings - Fork 210
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Create Dependabot config file #374
Conversation
This was autogenerated, we need to review it and adjust accordingly. |
✔️ Deploy Preview for pihole-docs ready! 🔨 Explore the source changes: fe92473 🔍 Inspect the deploy log: https://app.netlify.com/sites/pihole-docs/deploys/60e0cc6814656a00088f93a4 😎 Browse the preview: https://deploy-preview-374--pihole-docs.netlify.app |
Does anybody recall why The rest of the changes look good, they are just backported. |
The template was auto-generated. None of the contents are opinionated or chosen/excluded for any known reason. It's just what the bot wrote. |
It's not what the bot wrote; everything is migrated from the current config |
Reindent and remove unneeded ignore
246ff8d
to
479b218
Compare
It's a PR literally opened by the bot itself. |
Yeah, but it just migrated the current config. |
Then I have no reason why |
Must have been an old thing, but since we now include the top-level deps, it's moot. I think we can merge this :) |
The only thing we need to consider is that automerging does not currently work: dependabot/dependabot-core#1973 |
Thanks for finding that. I think the dependabot/dependabot-core#1973 (comment) solution is feasible. |
For security reasons, I would suggest that we stick with the current solution and block this PR until there's a proper solution in core. |
How about using as suggested in the referenced upstream issue (last comment)? |
SGTM. |
I believe GitHub now has some kind of auto-merge feature, not sure how good it works with dependabot, though. But this is the only way forward, although we might need to wait for the needed functionality from GitHub. |
As a reminder, Dependabot Preview will be shut down on August 3rd, 2021. You can merge this pull request to migrate to GitHub-native Dependabot. You can read the docs to learn more about what's changing, as well as find out how to get support if you need help migrating. |
Hold my beer.. we're going github native (we won't have any choice in a month anyway) |
👋 Dependabot is moving natively into GitHub! This pull request migrates your configuration from Dependabot.com to a config file, using the new syntax. When you merge this pull request, we'll swap out
dependabot-preview
(me) for a newdependabot
app, and you'll be all set!With this change, you'll now use the Dependabot page in GitHub, rather than the Dependabot dashboard, to monitor your version updates. Dependabot is now configured exclusively using config files.
If you've got any questions or feedback for us, please let us know by creating an issue in the dependabot/dependabot-core repository.
Learn more about the relaunch of Dependabot
Please note that regular
@dependabot
commands do not work on this pull request.🤖💛