-
Notifications
You must be signed in to change notification settings - Fork 1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Allow array in target-branch
#2511
Comments
That would be a great help especially for |
We are supporting multiple release lines for our package and it would be great to configure Dependabot to open PRs into each of these major branches (and checkout from the same branches). |
I wish it supported glob patterns, like Actions workflow on:
push:
branches:
- releases/** |
This would be of greate benefit for us as well. The Joomla project has somewhere around 200 repos, a large part of which has branches for 2 major development lines and each with its own dependencies. The limitation to only be able to check one branches dependencies is the reason we currently aren't using it. Especially since it seems the feature to support more than one branch was already part of dependabot before it was aquired by github. It would be really awesome for us if this would be adopted again. |
Any update on feature? |
I believe the original issue does not describe correctly the problem. Instead, I believe the author wants to have a configurable I´d need that feature too. Currently, I set the default branch to the |
@mildred Not really https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#target-branch
|
Is the target branch specific to GitHub dependabot? I was wondering how one can configure this as part of dependabot-core? |
Any progress on this? |
11563: chore(dependabot): patch dependency updates for stable branches r=megglos a=megglos ## Description This automates dependency updates for stable branches with dependabot, by only allowing PRs to be created for patch updates. It's unfortunate that dependabot does not yet support patterns and/or multiple target-branches, see this issue dependabot/dependabot-core#2511 . Thus we have to duplicate the config for every supported stable branch in the meantime. This would thus require a follow-up to be reflected in the release process for minor releases (add new config, remove out of support branches). Still I think it's worth the effort right now to automate eliminating vulnerabilities for which patched versions already exist. Ultimately preventing support effort caused by customers performing vulnerability analytics and raising issues like SEC-238. ## Related issues relates to #10553 Co-authored-by: Meggle (Sebastian Bathke) <[email protected]>
…ependabot/dependabot-core#2511) - let's try duplication
* check if dependabot allows multiple "target-branch" values * no, target-branch can't be array (dependabot/dependabot-core#2159 and dependabot/dependabot-core#2511) - let's try duplication
annoying that they currently don't support glob patterns or arrays (dependabot/dependabot-core#2511) Signed-off-by: Bohan Chen <[email protected]>
* check if dependabot allows multiple "target-branch" values * no, target-branch can't be array (dependabot/dependabot-core#2159 and dependabot/dependabot-core#2511) - let's try duplication
That would prevent us to have lots of duplicate configs
The text was updated successfully, but these errors were encountered: