Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Packages out of Date #37

Open
Sweetdevil144 opened this issue Jan 21, 2024 · 12 comments
Open

Packages out of Date #37

Sweetdevil144 opened this issue Jan 21, 2024 · 12 comments

Comments

@Sweetdevil144
Copy link
Contributor

I recently found 7 PRs over my for of web of DependableBots as shown in image below. I think a number of packages are out of date. Is there a way to automate the process to keep them up to date?
A number of packages offer a feature in package.json such as package@latest take Vite for example. But many don't.
Any approach or Suggestions ?

Screenshot 2024-01-21 at 12 20 00 PM
@Sweetdevil144
Copy link
Contributor Author

@RohanSasne check this out :
Screenshot 2024-01-21 at 3 58 34 PM

@allgandalf
Copy link
Collaborator

Busy for at-least the end of this month, can you bump me early next month @Sweetdevil144 ?

@Sweetdevil144
Copy link
Contributor Author

Yeah sure. I too am busy and have been since last month. Sems and stuff :)
I'll come up with a PR and notify you by the start of March.

@allgandalf
Copy link
Collaborator

I too am busy and have been since last month. Sems and stuff :)

I know, life happens to everyone of us, but end of day it’s important that we stay put to our commitments and show up sooner rather than later :)

please wait for the PR, I want to review the scope of this issue and can collaborate with you if we are covering this for larger project scope

@Sweetdevil144
Copy link
Contributor Author

Any Updates @GandalfGwaihir

@allgandalf
Copy link
Collaborator

A number of packages offer a feature in package.json such as package@latest take Vite for example

@Sweetdevil144 , i would rather prefer @stable branch that the latest one :)

Any approach or Suggestions ?

Only way to deal with this package upgrades is to use automation in place:
https://docs.github.com/en/code-security/dependabot/dependabot-version-updates

I got this awesome read about how to implement dependabot, do go through it and see if you can implement this, if you require any contributor access, ping me here, I'll grant it to you

And thanks a lot for the bump, this went out of my mind

@Sweetdevil144
Copy link
Contributor Author

@GandalfGwaihir below is the following instruction for configuring dependabot :

People with write permissions to a repository can enable or disable Dependabot version updates for the repository.

@allgandalf
Copy link
Collaborator

i guess i don't have access to settings, @robkooper , can you help here please :), either enable the bot or can you give me access to repository settings so that i can configure it myself, thanks

@robkooper
Copy link
Member

this is now enabled, lets see what happens.

@Sweetdevil144
Copy link
Contributor Author

Thanks @robkooper . I guess the issue is fixed now. So, we can close this issue for now. I will reopen this issue if I face any issues related to dependabot

@robkooper
Copy link
Member

I'd like to keep it open until we get the first PR by dependabot.

@allgandalf
Copy link
Collaborator

allgandalf commented Apr 29, 2024

this didn't work, PR closed in cyclic loop, anyway I am opening a PR in the main website repository over the weekend, I let's take this discussion over there :) (We are migrating the website, FINALLY!!!!!)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants