Conversation
ezio-melotti
left a comment
There was a problem hiding this comment.
It's unfortunate that there's no easy way to do it (unless target-branch: "3.*" works, but it's not documented).
This feature has been requested upstream before:
Here is the relevant documentation: https://docs.github.com/en/code-security/tutorials/secure-your-dependencies/customizing-dependabot-prs#targeting-pull-requests-against-a-non-default-branch
Also note this:
Dependabot raises pull requests for security updates against the default branch only. If you use
target-branch, then as a result, all configuration settings for that package manager will then only apply to version updates, and not security updates.
| cooldown: | ||
| default-days: 14 | ||
|
|
||
| - package-ecosystem: "pip" |
There was a problem hiding this comment.
I would move this to the top, so that all the main sections are together. Perhaps it should also be duplicated for all branches.
| labels: | ||
| - "skip issue" | ||
| - "skip news" | ||
| groups: | ||
| actions: | ||
| patterns: | ||
| - "*" |
There was a problem hiding this comment.
Since we are duplicating all lines and readability is less of a concern, maybe we could use this compact form instead:
| labels: | |
| - "skip issue" | |
| - "skip news" | |
| groups: | |
| actions: | |
| patterns: | |
| - "*" | |
| labels: ["skip issue", "skip news"] | |
| groups: | |
| actions: | |
| patterns: ["*"] |
These could be further reduced to this if we wanted to:
| labels: | |
| - "skip issue" | |
| - "skip news" | |
| groups: | |
| actions: | |
| patterns: | |
| - "*" | |
| labels: ["skip issue", "skip news"] | |
| groups: { actions: { patterns: ["*"] } } |
If we applied the latter to the whole block, each block will only take 7 lines (instead of 14)
Rather than backporting Dependabot updates, which will pretty much always have conflicts due to different workflows, and which we often forget to do (causing more conflicts), let's have Dependabot run on each branch.
The config belongs in
main, and unfortunately needs repeating, but each block is fairly small.(Renovate would allow us to use a regex and avoid the repetition, but that's a bigger move involving installing a new app. But I'm a happy Renovate user in other projects, so it's always an option for later.)