-
-
Notifications
You must be signed in to change notification settings - Fork 32.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[core] Introduce dependabot #16679
Merged
Merged
[core] Introduce dependabot #16679
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Details of bundle changes.Comparing: fd24690...2a30d22
|
This comment has been minimized.
This comment has been minimized.
eps1lon
force-pushed
the
auto-deps
branch
2 times, most recently
from
July 22, 2019 15:21
46396da
to
d7b1b9e
Compare
Upgrading raw-loader is a bit tricky since it uses ES6 modules now instead of commonJS. Once it includes features/bug fixes we can revisit. |
eps1lon
force-pushed
the
auto-deps
branch
7 times, most recently
from
July 23, 2019 08:47
368c0f5
to
1845319
Compare
* Bump enzyme from 3.9.0 to 3.10.0 Bumps [enzyme](https://github.com/airbnb/enzyme/tree/HEAD/packages/enzyme) from 3.9.0 to 3.10.0. - [Release notes](https://github.com/airbnb/enzyme/releases) - [Changelog](https://github.com/airbnb/enzyme/blob/master/CHANGELOG.md) - [Commits](https://github.com/airbnb/enzyme/commits/enzyme@3.10.0/packages/enzyme) Signed-off-by: dependabot-preview[bot] <support@dependabot.com> * Add dependabot badge * Fix failing test
Bumps [webpack-cli](https://github.com/webpack/webpack-cli) from 3.3.2 to 3.3.6. - [Release notes](https://github.com/webpack/webpack-cli/releases) - [Changelog](https://github.com/webpack/webpack-cli/blob/v3.3.6/CHANGELOG.md) - [Commits](webpack/webpack-cli@v3.3.2...v3.3.6) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [lodash.template](https://github.com/lodash/lodash) from 4.4.0 to 4.5.0. **This update includes security fixes.** - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.4.0...4.5.0) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [lodash](https://github.com/lodash/lodash) from 4.17.14 to 4.17.15. - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.14...4.17.15) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Updates the requirements on [react-docgen](https://github.com/reactjs/react-docgen) to permit the latest version. - [Release notes](https://github.com/reactjs/react-docgen/releases) - [Commits](reactjs/react-docgen@v5.0.0-beta.1...v5.0.0-beta.1) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Updates the requirements on [jss-rtl](https://github.com/alitaheri/jss-rtl) to permit the latest version. - [Release notes](https://github.com/alitaheri/jss-rtl/releases) - [Commits](alitaheri/jss-rtl@v0.2.1...v0.2.3) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Updates the requirements on [@material-ui/pickers](https://github.com/mui-org/material-ui-pickers) to permit the latest version. - [Release notes](https://github.com/mui-org/material-ui-pickers/releases) - [Commits](mui/material-ui-pickers@v3.1.1...v3.2.0) Signed-off-by: dependabot-preview[bot] <support@dependabot.com> Bump @date-io/date-fns from 1.3.5 to 1.3.8 (#93) Bumps [@date-io/date-fns](https://github.com/dmtrKovalenko/date-io) from 1.3.5 to 1.3.8. - [Release notes](https://github.com/dmtrKovalenko/date-io/releases) - [Commits](dmtrKovalenko/date-io@v1.3.5...v1.3.8) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
) Updates the requirements on [react-autosuggest](https://github.com/moroshko/react-autosuggest) to permit the latest version. - [Release notes](https://github.com/moroshko/react-autosuggest/releases) - [Commits](moroshko/react-autosuggest@v9.3.2...v9.4.3) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Updates the requirements on [redux](https://github.com/reduxjs/redux) to permit the latest version. - [Release notes](https://github.com/reduxjs/redux/releases) - [Changelog](https://github.com/reduxjs/redux/blob/master/CHANGELOG.md) - [Commits](reduxjs/redux@v4.0.0...v4.0.4) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Updates the requirements on [jscodeshift](https://github.com/facebook/jscodeshift) to permit the latest version. - [Release notes](https://github.com/facebook/jscodeshift/releases) - [Changelog](https://github.com/facebook/jscodeshift/blob/master/CHANGELOG.md) - [Commits](facebook/jscodeshift@v0.6.0...v0.6.4) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Updates the requirements on [warning](https://github.com/BerkeleyTrue/warning) to permit the latest version. - [Release notes](https://github.com/BerkeleyTrue/warning/releases) - [Changelog](https://github.com/BerkeleyTrue/warning/blob/master/CHANGELOG.md) - [Commits](BerkeleyTrue/warning@v4.0.1...v4.0.3) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Updates the requirements on [react-is](https://github.com/facebook/react/tree/HEAD/packages/react-is) to permit the latest version. - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/facebook/react/blob/master/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v16.8.6/packages/react-is) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Updates the requirements on [marked](https://github.com/markedjs/marked) to permit the latest version. - [Release notes](https://github.com/markedjs/marked/releases) - [Commits](markedjs/marked@v0.6.0...v0.7.0) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [typescript](https://github.com/Microsoft/TypeScript) from 3.2.2 to 3.2.4. - [Release notes](https://github.com/Microsoft/TypeScript/releases) - [Commits](microsoft/TypeScript@v3.2.2...v3.2.4) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [material-ui-popup-state](https://github.com/jcoreio/material-ui-popup-state) from 1.3.2 to 1.4.0. - [Release notes](https://github.com/jcoreio/material-ui-popup-state/releases) - [Commits](jcoreio/material-ui-popup-state@v1.3.2...v1.4.0) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [danger](https://github.com/danger/danger-js) from 7.1.4 to 9.1.3. - [Release notes](https://github.com/danger/danger-js/releases) - [Changelog](https://github.com/danger/danger-js/blob/master/CHANGELOG.md) - [Commits](danger/danger-js@7.1.4...9.1.3) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [react-window](https://github.com/bvaughn/react-window) from 1.8.1 to 1.8.5. - [Release notes](https://github.com/bvaughn/react-window/releases) - [Changelog](https://github.com/bvaughn/react-window/blob/master/CHANGELOG.md) - [Commits](bvaughn/react-window@1.8.1...1.8.5) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [@types/enzyme](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/enzyme) from 3.9.1 to 3.10.3. - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/enzyme) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [eslint-plugin-jsx-a11y](https://github.com/evcohen/eslint-plugin-jsx-a11y) from 6.2.1 to 6.2.3. - [Release notes](https://github.com/evcohen/eslint-plugin-jsx-a11y/releases) - [Changelog](https://github.com/evcohen/eslint-plugin-jsx-a11y/blob/master/CHANGELOG.md) - [Commits](infofarmer/eslint-plugin-jsx-a11y@v6.2.1...v6.2.3) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
* Bump rollup-plugin-terser from 5.0.0 to 5.1.1 Bumps [rollup-plugin-terser](https://github.com/TrySound/rollup-plugin-terser) from 5.0.0 to 5.1.1. - [Release notes](https://github.com/TrySound/rollup-plugin-terser/releases) - [Commits](TrySound/rollup-plugin-terser@v5.0.0...v5.1.1) Signed-off-by: dependabot-preview[bot] <support@dependabot.com> * Bump terser related deps
Bumps [lerna](https://github.com/lerna/lerna/tree/HEAD/core/lerna) from 3.16.2 to 3.16.3. - [Release notes](https://github.com/lerna/lerna/releases) - [Changelog](https://github.com/lerna/lerna/blob/master/core/lerna/CHANGELOG.md) - [Commits](https://github.com/lerna/lerna/commits/v3.16.3/core/lerna) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [@types/react-router-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-router-dom) from 4.3.2 to 4.3.4. - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-router-dom) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [@babel/node](https://github.com/babel/babel) from 7.2.2 to 7.5.5. - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/master/CHANGELOG.md) - [Commits](babel/babel@v7.2.2...v7.5.5) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [eslint-config-airbnb](https://github.com/airbnb/javascript) from 17.1.0 to 17.1.1. - [Release notes](https://github.com/airbnb/javascript/releases) - [Commits](airbnb/javascript@eslint-config-airbnb-v17.1.0...eslint-config-airbnb-v17.1.1) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [babel-plugin-istanbul](https://github.com/istanbuljs/babel-plugin-istanbul) from 5.1.4 to 5.2.0. - [Release notes](https://github.com/istanbuljs/babel-plugin-istanbul/releases) - [Changelog](https://github.com/istanbuljs/babel-plugin-istanbul/blob/master/CHANGELOG.md) - [Commits](istanbuljs/babel-plugin-istanbul@v5.1.4...v5.2.0) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [@types/react-transition-group](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-transition-group) from 2.9.2 to 4.2.0. - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-transition-group) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [final-form](https://github.com/final-form/final-form) from 4.12.0 to 4.18.2. - [Release notes](https://github.com/final-form/final-form/releases) - [Commits](final-form/final-form@v4.12.0...v4.18.2) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
eps1lon
force-pushed
the
auto-deps
branch
2 times, most recently
from
July 23, 2019 21:49
4a271f3
to
7ce9d2a
Compare
Bumps [lerna](https://github.com/lerna/lerna/tree/HEAD/core/lerna) from 3.16.3 to 3.16.4. - [Release notes](https://github.com/lerna/lerna/releases) - [Changelog](https://github.com/lerna/lerna/blob/master/core/lerna/CHANGELOG.md) - [Commits](https://github.com/lerna/lerna/commits/v3.16.4/core/lerna) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
💯 for trying it and learning from it |
This was referenced Jul 24, 2019
oliviertassinari
approved these changes
Jul 24, 2019
merceyz
reviewed
Jul 24, 2019
@@ -17,6 +17,7 @@ | |||
[![CII Best Practices](https://bestpractices.coreinfrastructure.org/projects/1320/badge)](https://bestpractices.coreinfrastructure.org/projects/1320) | |||
![Code style](https://img.shields.io/badge/code_style-prettier-ff69b4.svg) | |||
[![Follow on Twitter](https://img.shields.io/twitter/follow/MaterialUI.svg?label=follow+Material-UI)](https://twitter.com/MaterialUI) | |||
[![Dependabot Status](https://api.dependabot.com/badges/status?host=github&repo=eps1lon/material-ui)](https://dependabot.com) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Suggested change
[![Dependabot Status](https://api.dependabot.com/badges/status?host=github&repo=eps1lon/material-ui)](https://dependabot.com) | |
[![Dependabot Status](https://api.dependabot.com/badges/status?host=github&repo=mui-org/material-ui)](https://dependabot.com) |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Updates were filed by https://dependabot.com/ which was recently acquired by GitHub and is free of charge.
On a configured schedule (live, daily, weekly) it files pull request for each dependency update. One PR per change is good because it helps isolating and fixing breaking changes. Examples:
I would propose enabling it for the main repo so that I don't have to batch and file changes to get access to CI. This is really time consuming. If it creates too much noise we can just disable it. It doesn't get easier than this.
Control happens via comments towards the bot e.g.
@dependabot ignore this minor
. This can be helpful if a package accidentally introduced breaking changes or we were using it in an unofficial way. We can shut down dependabot until such a dependency introduces interesting features/fixes that we really want to included and fixing breaking changes becomes valueable.The overall goal is to reduce maintenance burden which is (IMO) mainly achieved by:
@dependabot merge
command (merges as soon as CI is green): especially helpful for dependencies that are well covered by CI (e.g. test utils)TODO:
master
and change to weekly preferably a monday since we usually release on the weekend)used the following config
deferred bumps: