From 355b331e207f2cd4125ca119f0b0bb0352f25883 Mon Sep 17 00:00:00 2001 From: Jonno Date: Tue, 16 Sep 2025 11:28:04 +0000 Subject: [PATCH 1/2] updated dependabot schedule --- .devcontainer/Dockerfile | 2 +- .devcontainer/devcontainer.json | 29 ++++++++++------------------- .github/dependabot.yml | 28 ++++++++++++++++++++++------ 3 files changed, 33 insertions(+), 26 deletions(-) diff --git a/.devcontainer/Dockerfile b/.devcontainer/Dockerfile index ef8e09fe..dc7fa929 100644 --- a/.devcontainer/Dockerfile +++ b/.devcontainer/Dockerfile @@ -9,7 +9,7 @@ RUN apt-get update \ jq apt-transport-https ca-certificates gnupg-agent \ software-properties-common bash-completion python3-pip make libbz2-dev \ libreadline-dev libsqlite3-dev wget llvm libncurses5-dev libncursesw5-dev \ - xz-utils tk-dev liblzma-dev netcat ruby-full build-essential zlib1g-dev \ + xz-utils tk-dev liblzma-dev netcat-traditional ruby-full build-essential zlib1g-dev \ && apt remove -y openjdk-8-jdk-headless openjdk-8-jre-headless openjdk-8-jre # install aws stuff diff --git a/.devcontainer/devcontainer.json b/.devcontainer/devcontainer.json index 771b5b93..046e505f 100644 --- a/.devcontainer/devcontainer.json +++ b/.devcontainer/devcontainer.json @@ -13,14 +13,6 @@ "source=${env:HOME}${env:USERPROFILE}/.ssh,target=/home/vscode/.ssh,type=bind", "source=${env:HOME}${env:USERPROFILE}/.gnupg,target=/home/vscode/.gnupg,type=bind" ], - // Features to add to the dev container. More info: https://containers.dev/features. - "features": { - "ghcr.io/devcontainers/features/docker-outside-of-docker:1": { - "version": "latest", - "moby": "true", - "installDockerBuildx": "true" - } - }, "customizations": { "vscode": { "extensions": [ @@ -61,16 +53,15 @@ } } }, - "remoteEnv": { "LOCAL_WORKSPACE_FOLDER": "${localWorkspaceFolder}" }, - "postCreateCommand": "rm -f ~/.docker/config.json; git config --global --add safe.directory /workspaces/eps-FHIR-validator-lambda; make install" - // "features": {}, - // Use 'forwardPorts' to make a list of ports inside the container available locally. - // "forwardPorts": [], - // Use 'postCreateCommand' to run commands after the container is created. - // "postCreateCommand": "" - // Configure tool-specific properties. - // "customizations": {}, - // Uncomment to connect as root instead. More info: https://aka.ms/dev-containers-non-root. - // "remoteUser": "root" + "remoteEnv": { "LOCAL_WORKSPACE_FOLDER": "${localWorkspaceFolder}" }, + "postAttachCommand": "docker build -f https://raw.githubusercontent.com/NHSDigital/eps-workflow-quality-checks/refs/tags/v4.0.4/dockerfiles/nhsd-git-secrets.dockerfile -t git-secrets . && poetry run pre-commit install --install-hooks -f", + "features": { + "ghcr.io/devcontainers/features/docker-outside-of-docker:1": { + "version": "latest", + "moby": "true", + "installDockerBuildx": "true" + }, + "ghcr.io/devcontainers/features/github-cli:1": {} + } } diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 0f743419..1377d357 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -19,9 +19,14 @@ updates: # default location of `.github/workflows` directory: "/" schedule: - interval: "daily" + interval: "weekly" + day: "friday" + time: "18:00" # UTC + open-pull-requests-limit: 20 commit-message: prefix: "Upgrade: [dependabot] - " + versioning-strategy: increase + ################################### # Java workspace ################## @@ -30,10 +35,14 @@ updates: directory: "/" rebase-strategy: "disabled" schedule: - interval: "daily" + interval: "weekly" + day: "friday" + time: "18:00" # UTC open-pull-requests-limit: 20 commit-message: prefix: "Upgrade: [dependabot] - " + versioning-strategy: increase + ################################### # Poetry ######################### @@ -41,10 +50,14 @@ updates: - package-ecosystem: "pip" directory: "/" schedule: - interval: "daily" - versioning-strategy: increase + interval: "weekly" + day: "friday" + time: "18:00" # UTC + open-pull-requests-limit: 20 commit-message: prefix: "Upgrade: [dependabot] - " + versioning-strategy: increase + ################################### # NPM workspace ################## @@ -52,7 +65,10 @@ updates: - package-ecosystem: "npm" directory: "/" schedule: - interval: "daily" - versioning-strategy: increase + interval: "weekly" + day: "friday" + time: "18:00" # UTC + open-pull-requests-limit: 20 commit-message: prefix: "Upgrade: [dependabot] - " + versioning-strategy: increase From ca9e80c3b76a083cb64937b9641421295418545d Mon Sep 17 00:00:00 2001 From: Jonno Date: Wed, 17 Sep 2025 15:41:12 +0000 Subject: [PATCH 2/2] removed versioning strategies --- .github/dependabot.yml | 2 -- 1 file changed, 2 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 1377d357..0a9ababf 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -25,7 +25,6 @@ updates: open-pull-requests-limit: 20 commit-message: prefix: "Upgrade: [dependabot] - " - versioning-strategy: increase ################################### @@ -41,7 +40,6 @@ updates: open-pull-requests-limit: 20 commit-message: prefix: "Upgrade: [dependabot] - " - versioning-strategy: increase ###################################