Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Make dependabot ignore patch updates #128

Merged
merged 2 commits into from
Jul 24, 2024

Conversation

mikealfare
Copy link
Contributor

Problem

We get dependabot updates for every release, including patch releases. We tend to soft pin to the minor for build dependencies and to the major for dev dependencies.

Solution

Make dependabot ignore patch releases.

Checklist

  • I have read the contributing guide and understand what's expected of me
  • I have run this code in development and it appears to resolve the stated issue
  • This PR includes tests, or tests are not required/relevant for this PR
  • This PR has no interface changes (e.g. macros, cli, logs, json artifacts, config files, adapter interface, etc) or this PR has already received feedback and approval from Product or DX

@mikealfare mikealfare self-assigned this Jul 20, 2024
@mikealfare mikealfare requested a review from a team as a code owner July 20, 2024 01:08
@cla-bot cla-bot bot added the cla:yes label Jul 20, 2024
@mikealfare mikealfare merged commit 2854173 into main Jul 24, 2024
21 checks passed
@mikealfare mikealfare deleted the make-dependabot-less-aggressive branch July 24, 2024 16:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants