dependabot / dependabot/dependabot-core

Audit the version update behavior across ecosystems

Open
#10,187 0 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Ecosystems Epic L: git:submodules L: python
Dominant language
Ruby
Stars
5.8k
Forks
1.5k
Avg merge
2d 13h
Merged PRs (30d)
151

Description

There are a variety of issues that have been raised indicating inconsistencies with the version update behavior. For example, this issue for pip, which has triggered a potential fix, but it's unclear if this is the right way to handle this, given the long precedent of existing behavior that users rely on.

Instead of making a one-off fix for pip that may result in even more inconsistencies, we instead should undertake an audit of the version update behavior across ecosystems. This will give us a better view into how these options are working across the board, before deciding what (if any) changes we should make to the existing behavior.

Some recent pertinent issues, feel free to link more:

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the linked issues 6630, 6631, 6519, and 10130, along with pull request 10060 and the checklist items. Done means producing a cross-ecosystem audit of version update behavior and identifying whether existing inconsistencies should change; the payload names no files, tests, or entry points.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
tooling
Issue type
Refactor
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.