Run Dependabot independently on each branch - #158361
Conversation
ezio-melotti
left a comment
There was a problem hiding this comment.
It's unfortunate that there's no easy way to do it (unless target-branch: "3.*" works, but it's not documented).
This feature has been requested upstream before:
Here is the relevant documentation: https://docs.github.com/en/code-security/tutorials/secure-your-dependencies/customizing-dependabot-prs#targeting-pull-requests-against-a-non-default-branch
Also note this:
Dependabot raises pull requests for security updates against the default branch only. If you use
target-branch, then as a result, all configuration settings for that package manager will then only apply to version updates, and not security updates.
| cooldown: | ||
| default-days: 14 | ||
|
|
||
| - package-ecosystem: "pip" |
There was a problem hiding this comment.
I would move this to the top, so that all the main sections are together. Perhaps it should also be duplicated for all branches.
There was a problem hiding this comment.
Duplicated for bugfix branches only: updating mypy for security branches may need code changes which we don't want to do for security. Hypothesis is the other pip thing, which I'm not sure needs regular updates for security either. We can do manual backports if something is needed?
Moved to the top, so we have:
- GHA main
- pip main
- GHA bugfix+security
- pip bugfix
I also added grouping for pip updates, so we get a single PR per branch instead of several per branch.
Yeah. If this becomes a pain, we can switch to Renovate and replace the repetition with a regex.
Good to know. So we might need to do our own backports of those. |
|
This worked :)
We do need to edit the titles to prefix And because it's a fresh update, Dependabot updates all files, which are easier to miss when manually backporting. Plus the title counts are accurate. Compare: |
Rather than backporting Dependabot updates, which will pretty much always have conflicts due to different workflows, and which we often forget to do (causing more conflicts), let's have Dependabot run on each branch.
The config belongs in
main, and unfortunately needs repeating, but each block is fairly small.(Renovate would allow us to use a regex and avoid the repetition, but that's a bigger move involving installing a new app. But I'm a happy Renovate user in other projects, so it's always an option for later.)