ministryofjustice / ministryofjustice/developer-experience-github-audit
Develop Dependency Management Tooling Guidance
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 2
- Forks
- 2
- Avg merge
- 10d 5h
- Merged PRs (30d)
- 2
Description
🧑💼 User Need
As a member of the DevX team
I want published guidance for the agreed dependency management tool
so that teams have a clear set of documentation covering setup, configuration, and best practice to reference when onboarding or reviewing their dependency management approach
💡 Value / Purpose
- Existing Depdendabot usage guidelines are already in place on the portal - this ticket ensuures equivalent guidance exists for whichever tool is agreed as the org standard, adn the guidance is published for consistent access.
🛠️ Description / Context
- Verify the current state of existing Dependabot guidance - location, completeness, and whether it needs updating in lieu of #231
- Based on the agreed strategy:
- if Dependabot: Review and update existing guidance, ensuring it covers the core tech stack of MoJ and DevX repos at least.
- If Renovate: Develop equivalent guidance from scratch covering the same scope
- If a migration period is required, develop guidance for both tools covering the transition and migrations steps
Any guidance should cover:
- Initial setup
- Recommended configuration (reference templates if needed)
- Ecosystem coverage
- Auto-merge vs manual review approaches
- SLA expectations for PRs
- Publush to the engineering portal or DevX-documentation site (decision-dependent) under an appropriate section
✅ Definition of Done
- Existing Dependabot guidance reviewed and updated where required
- Guidance developed for agreed tool covering all relevant ecosystems
- Transition guidance developed to cover off migration period
- Guidance published to DevX documentation site or appropriate
- Findings shared with wider team where applicable
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the existing Dependabot guidance on the engineering portal and checking the agreed strategy in #231. Document the selected tool's setup, configuration, ecosystem coverage, review approach, and SLA expectations, then publish it to the agreed DevX documentation location and complete the listed definition-of-done checks.
Written by the indexing model from the issue text.
Assessment
- Domain
- developer-experience, documentation
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100