Skip to content

Conversation

@JacobCoffee
Copy link
Member

@JacobCoffee JacobCoffee commented Sep 19, 2024

Description

  • Updates config to combine dependabot PRs weekly

Other Option #2591

@shenxianpeng

This comment was marked as resolved.

@JacobCoffee
Copy link
Member Author

I haven't merged this yet because we have a bunch of packages from the Django 2 migration that were bare-minimum bumped up to where they support 4.2, and as you may see in the PRs there are many dependabots saying "bump projectX==3.123 to 8.1!" and i dont want this to bring in all that mess and stomp on the important ones i do have time to look at and merge (CVE-related mostly)

I will continue my work in #2741 when pycon craziness settles or when i get a wild hair at night as part of cpython triage (I don’t know if that counts? its fun though either way!) and THEN work on bumping packages up and then finally merge this... unless someone has a better idea or thinks i am thinking this through poorly :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants