Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Maintain dependencies using dependabot #39

Closed
foolip opened this issue Sep 12, 2019 · 6 comments
Closed

Maintain dependencies using dependabot #39

foolip opened this issue Sep 12, 2019 · 6 comments

Comments

@foolip
Copy link
Member

foolip commented Sep 12, 2019

https://dependabot.com/ sends PRs for node dependencies, and I've found it to be quite nice for some other personal projects.

@domenic have you used this, and WDYT?

@domenic
Copy link
Member

domenic commented Sep 13, 2019

I've not used it. I'd be happy to do this if you're able to set it up :)

@foolip
Copy link
Member Author

foolip commented Sep 13, 2019

Alright, I'll enable it and look at the PRs it sends.

@foolip
Copy link
Member Author

foolip commented Sep 13, 2019

A bunch of PRs have been sent now. Per #4 test coverage isn't perfect.

@domenic merging will automatically deploy, but is there any sort of precaution you'd want to take beyond seeing tests pass?

@domenic
Copy link
Member

domenic commented Sep 13, 2019

I think it'll probably be fine... I mean, ideally we'd get the additional coverage, but I don't think we should block on that.

@foolip
Copy link
Member Author

foolip commented Sep 13, 2019

I've merged a number of PRs that seemed low risk now and it seems fine. Will keep merging the smallest possible changes to resolve npm audit issues, and see what's then left.

@foolip
Copy link
Member Author

foolip commented Sep 13, 2019

Closing this since Dependabot is set up. I'll watch the repo to see the PRs as well.

@foolip foolip closed this as completed Sep 13, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

2 participants