Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ci: 👷 fix dependabot or switch to renovate #416

Closed
6 tasks
karlbaumhauer opened this issue Sep 19, 2023 · 2 comments · Fixed by #453
Closed
6 tasks

ci: 👷 fix dependabot or switch to renovate #416

karlbaumhauer opened this issue Sep 19, 2023 · 2 comments · Fixed by #453
Assignees
Labels

Comments

@karlbaumhauer
Copy link
Contributor

karlbaumhauer commented Sep 19, 2023

User Story

As a developer of the Solid Design System, I would like to have all dependencies regularly updated and checked for vulnerabilities, so that I am sure our project dependencies are secure and well maintained.

Suggested Solution

As dependabot seems to have issues with pnpm (even thought it is supposed to work), I suggest to quickly have a look into possible fixes and, if it cant be fixed right away, switch to renovate as this works fine in the CMS's monorepo with pnpm.

Environment (GitHub Actions or Azure DevOps)

GitHub

Technical Information

DoR

  • Item has business value
  • Item has been estimated by the team
  • Item is clear and well-defined
  • Item dependencies have been identified

DoD

  • Documentation has been created/updated (if applicable)
  • Implementation works successfully on feature branch
@mariohamann
Copy link
Contributor

mariohamann commented Sep 25, 2023

If this is not going to be fixed soon, we at least should remove Dependabot and all related PRs as this doesn't show our repo in a good shape, bloats our PR overview and our mail inbox. @Vahid1919 @karlbaumhauer

@Vahid1919 Vahid1919 mentioned this issue Sep 29, 2023
2 tasks
@karlbaumhauer
Copy link
Contributor Author

@Vahid1919 if you have time and there is nothing left in the milestone to focus on, you could start here... If you need access to the mentioned implementation on azure devops, let me know.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
Development

Successfully merging a pull request may close this issue.

3 participants