Skip to content

Update deps and add dependabot.yml#48

Merged
oschwartz10612 merged 8 commits into
fosrl:devfrom
Lokowitz:main
Jun 2, 2025
Merged

Update deps and add dependabot.yml#48
oschwartz10612 merged 8 commits into
fosrl:devfrom
Lokowitz:main

Conversation

@Lokowitz

@Lokowitz Lokowitz commented Jun 1, 2025

Copy link
Copy Markdown
Contributor

Community Contribution License Agreement

By creating this pull request, I grant the project maintainers an unlimited,
perpetual license to use, modify, and redistribute these contributions under any terms they
choose, including both the AGPLv3 and the Fossorial Commercial license terms. I
represent that I have the right to grant this license for all contributed content.

Description

  • updated dependencies
  • added dependabot.yml

Please let me know if you want to use dependabot. It's easy to enable Settings->Advanced Security see docs

firecat53 and others added 8 commits April 6, 2025 16:40
Flake update for newt 1.1.3
Bumps the minor-updates group with 2 updates: golang and alpine.


Updates `golang` from 1.23.1-alpine to 1.24.3-alpine

Updates `alpine` from 3.19 to 3.22

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.24.3-alpine
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-updates
- dependency-name: alpine
  dependency-version: '3.22'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps the prod-minor-updates group with 1 update: [golang.org/x/net](https://github.com/golang/net).


Updates `golang.org/x/net` from 0.30.0 to 0.40.0
- [Commits](golang/net@v0.30.0...v0.40.0)

---
updated-dependencies:
- dependency-name: golang.org/x/net
  dependency-version: 0.40.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-minor-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
…62732f451

Bump the minor-updates group with 2 updates
…updates-5e519fa3dd

Bump golang.org/x/net from 0.30.0 to 0.40.0 in the prod-minor-updates group
@oschwartz10612

Copy link
Copy Markdown
Member

Thanks so much as always! Enabled Dependabot.

@oschwartz10612 oschwartz10612 merged commit 6935c3b into fosrl:dev Jun 2, 2025
@Lokowitz

Lokowitz commented Jun 2, 2025

Copy link
Copy Markdown
Contributor Author

@oschwartz10612 i am happy to help out :)
Dependabot is just checking the main/default branch and created the PR for this. There is an option to change it to dev branch docs but then you miss Options defined for this package-ecosystem no longer apply to security updates because security updates always use the default branch for the repository.
Do you want to switch it to dev or maybe switch the default branch to dev?

@oschwartz10612

Copy link
Copy Markdown
Member

That's a good question. Not sure if we want dev to be default or not. Let me talk to @miloschwartz

@Lokowitz

Lokowitz commented Jun 3, 2025

Copy link
Copy Markdown
Contributor Author

@oschwartz10612 @miloschwartz
Guys, please keep in mind that i have already submitted a lot of updated versions in my PR to dev (in pangolin, docs, gerbil and newt).
By approving the PRs from dependabot into main you may get merging errors when you want to merge dev into main.
I think it's better to first merge dev into main and then go ahead with the dependabot PRs.
This was the reason it tried to close a PR from dependabot yesterday, but i am not able to do this :-D

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants