switch to dependabot (ichnaea)
Categories
(Location :: General, task, P1)
Tracking
(Not tracked)
People
(Reporter: willkg, Assigned: willkg)
Details
Attachments
(1 file)
Seems like pyup is dead. There are several options to switch to, one of which is dependabot. dependabot seems fine except that it doesn't do batch updates, so it'll create one PR per library that needs updating.
There's an issue for implementing batch updates, so I think that'll happen eventually.
In the meantime, having that even without the batch updates is significantly better than having pyup do nothing and having to assemble it by hand.
Assignee | ||
Comment 1•5 years ago
|
||
I think I have access to add this to Ichnaea. Grabbing this to do now.
I'll set it up similarly to how we set up pyup.
Assignee | ||
Comment 2•5 years ago
|
||
Assignee | ||
Comment 3•5 years ago
|
||
Assignee | ||
Comment 4•5 years ago
|
||
I added ichnaea to dependabot and now the PRs are flowing in. OMG.
The next step is to shut off pyup. I don't know how to do that offhand. I did remove the config file, but if pyup ever starts working again, it'll switch to the default configuration for the org. That would be unenthusing.
Assignee | ||
Comment 5•5 years ago
|
||
Ichnaea is on dependabot and got a slew of PRs.
Ichnaea is no longer in pyup (thank you, Greg!).
We're done here.
Assignee | ||
Comment 6•5 years ago
|
||
Oh, whoops--it's not removed from pyup, yet. I'm re-opening.
Assignee | ||
Updated•5 years ago
|
Assignee | ||
Comment 7•5 years ago
|
||
Ichnaea is now removed from pyup. We're all done here.
Description
•