Skip to content
This repository has been archived by the owner on Nov 23, 2023. It is now read-only.

Review how frequent Dependabot updates packages #2291

Open
Jimlinz opened this issue Nov 10, 2022 · 1 comment
Open

Review how frequent Dependabot updates packages #2291

Jimlinz opened this issue Nov 10, 2022 · 1 comment
Labels
enabler story Enable to team to improve

Comments

@Jimlinz
Copy link
Contributor

Jimlinz commented Nov 10, 2022

Enabler

So that we optimise GitHub Action workflow minutes and costs, we want to review how often Dependabot bump packages for an update.
Dependabot currently scans for new package update daily. Some of the packages in Geostore are updated frequently. This isn't necessarily a bad thing, but it does incur an overhead cost where each Dependabot Pull Request triggers a 40minute workflow run (only to be superseded by another update the following day).

Perhaps a weekly update would be a good balance? This way we would skip a handful of minor package updates during the week (especially for packages that do a release daily). We should discuss as a team to establish what is best for Geostore.

Other considerations:
  1. We should work out if there is a way to override this for security updates, so we don't end up waiting a week before a security update is applied.
  2. Reduce update frequency for now, but have another review / discussion when Geostore becomes public?
@Jimlinz Jimlinz added the enabler story Enable to team to improve label Nov 10, 2022
@billgeo billgeo moved this to 📋 Backlog in Data Infrastructure Squad Nov 20, 2022
@billgeo
Copy link
Contributor

billgeo commented Nov 20, 2022

Sounds like a good idea to me.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
enabler story Enable to team to improve
Development

No branches or pull requests

2 participants