-
Type:
Task
-
Resolution: Unresolved
-
Priority:
Major - P3
-
None
-
Affects Version/s: None
-
Component/s: None
Context
We get a lot of Dependabot PRs that update dependencies in multiple modules across the Go Driver repo. Almost all of them require edits before they can be merged because they change dependencies in the main module that can't be changed for various reasons. For example, we have to plan minimum Go version bumps, so a dependency that requires we change the go directive needs more consideration than one that does not.
It's possible to configure Dependabot to treat dependencies in different modules differently. See the Nodejs Dependabot config for an example.
Open questions:
Q. Can we require Dependabot bump dependencies in the main module one-at-a-time?
A. ?
Q. Should we tell Dependabot to ignore all dependencies in the main module and just update them manually?
A. No, that would practically mean that main Go Driver module dependencies don't get updated on any cadence.
Definition of done
- Update the Dependabot config at .github/dependabot.yml to handle main module dependencies different than submodule dependencies.
- Non-published submodule dependencies should always be updated to latest.
- Published submodule dependencies should be updated one-at-a-time, and only some can be updated.
- Figure out which dependencies need to be ignored/pinned and ignore/pin them in the config.
Pitfalls
What should the implementer watch out for? What are the risks?