Configure Dependabot + Documentation #53
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
I configured our repository to use Dependabot. Specific details about the agreed-upon workflow (which is subject to change) can be found in
DEPENDABOT.md, but essentially, this will allow us to update our dependencies as newer versions become available.Changes Made
Testing & Verification
Verification Steps:
I forked the repository and added
dependabot.ymlto that. Dependabot then started making PRs concerning updates to the Dockerfile, npm/yarn packages, and GitHub Actions (also note that since Bew is an automatic assignee, Dependabot was yelling that it couldn't find him in the forked repo, which is to be expected)Screenshots (if relevant)
Future Improvements/Notes
Before merging, it would be good to have the entire team agree on a process for reviewing Dependabot's PRs and updating dependencies as needed.
Related Issues
Closes #45