Skip to content

Configure dependabot to handle rubygems dependencies#9445

Merged
jekyllbot merged 3 commits intomasterfrom
rubygems-dependabot-config
Oct 31, 2023
Merged

Configure dependabot to handle rubygems dependencies#9445
jekyllbot merged 3 commits intomasterfrom
rubygems-dependabot-config

Conversation

@mattr-
Copy link
Copy Markdown
Member

@mattr- mattr- commented Sep 13, 2023

This is a 🔨 code refactoring.

Summary

This updates our dependabot config for jekyll to allow it to bump ruby dependencies. It also attempting to configure update grouping so we can potentially avoid large numbers of PRs that bump individual gems in favor of larger group updates

@mattr- mattr- requested a review from a team October 22, 2023 17:26
Copy link
Copy Markdown
Member

@parkr parkr left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe add jekyll/core as a reviewer?

We can try the groupings for a bit. If we find we often want to accept only part of the group then we can try individual updates. I suspect the first wave of updates will be the biggest.

@parkr
Copy link
Copy Markdown
Member

parkr commented Oct 22, 2023

Maybe add jekyll/core as a reviewer?

Specifically, add as a reviewer of dependabot PRs :)

@mattr-
Copy link
Copy Markdown
Member Author

mattr- commented Oct 22, 2023

Good idea. I think I'll also ungroup for now and then once we're in a place where we're not having to update the world all the time, we can attempt grouping again.

@mattr- mattr- force-pushed the rubygems-dependabot-config branch from de68b13 to 9f9a885 Compare October 22, 2023 21:43
@mattr-
Copy link
Copy Markdown
Member Author

mattr- commented Oct 31, 2023

Added jekyll/core as a reviewer and did the ungrouping. CI is clean. Going to use @parkr's prior approval and merge it.

@jekyllbot: merge +dev

@jekyllbot jekyllbot merged commit cd4d84a into master Oct 31, 2023
@jekyllbot jekyllbot deleted the rubygems-dependabot-config branch October 31, 2023 15:59
jekyllbot added a commit that referenced this pull request Oct 31, 2023
github-actions bot pushed a commit that referenced this pull request Oct 31, 2023
Matt Rogers: Configure dependabot to handle rubygems dependencies (#9445)

Merge pull request 9445
@jekyll jekyll locked and limited conversation to collaborators Oct 30, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants