Skip to content

Conversation

@davdhacs
Copy link
Contributor

Could we use the dependabot metadata and gh cli to do the auto-merge for minor/patch dependabot pr's?

re: https://issues.redhat.com/browse/ROX-25705 and the external action. It could be nice to remove one external action dependency because that action does not appear to have updated documentation around the security issue that we encountered. I think then the automerge could be integrated more with the dependabot and github repository configuration in the future: If automerge is turned on for the repo then this could be switched to auto-approve. And specific dependancies and versions can be added if needed (and following the github documentation instead of relying on the action code+docs).

@davdhacs davdhacs requested a review from janisz August 22, 2024 17:30
@davdhacs
Copy link
Contributor Author

I'll merge this one and we can see if it works as well as the automerge action?

@davdhacs davdhacs merged commit 9550cdd into main Aug 26, 2024
@davdhacs davdhacs deleted the ROX-25705-dependabot-builtin-not-external-automerge branch August 26, 2024 13:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants