dependabot / dependabot/dependabot-core
Audit the version update behavior across ecosystems
Nobody has claimed this yet.
- Dominant language
- Ruby
- Stars
- 5.8k
- Forks
- 1.5k
- Avg merge
- 2d 13h
- Merged PRs (30d)
- 151
Description
There are a variety of issues that have been raised indicating inconsistencies with the version update behavior. For example, this issue for pip, which has triggered a potential fix, but it's unclear if this is the right way to handle this, given the long precedent of existing behavior that users rely on.
Instead of making a one-off fix for pip that may result in even more inconsistencies, we instead should undertake an audit of the version update behavior across ecosystems. This will give us a better view into how these options are working across the board, before deciding what (if any) changes we should make to the existing behavior.
Some recent pertinent issues, feel free to link more:
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the linked issues 6630, 6631, 6519, and 10130, along with pull request 10060 and the checklist items. Done means producing a cross-ecosystem audit of version update behavior and identifying whether existing inconsistencies should change; the payload names no files, tests, or entry points.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- tooling
- Issue type
- Refactor
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100