ministryofjustice / ministryofjustice/developer-experience-github-audit

Develop Dependency Management Tooling Guidance

Open
#233 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
2
Forks
2
Avg merge
10d 5h
Merged PRs (30d)
2

Description

🧑‍💼 User Need

As a member of the DevX team
I want published guidance for the agreed dependency management tool
so that teams have a clear set of documentation covering setup, configuration, and best practice to reference when onboarding or reviewing their dependency management approach

💡 Value / Purpose

  • Existing Depdendabot usage guidelines are already in place on the portal - this ticket ensuures equivalent guidance exists for whichever tool is agreed as the org standard, adn the guidance is published for consistent access.

🛠️ Description / Context

  • Verify the current state of existing Dependabot guidance - location, completeness, and whether it needs updating in lieu of #231
  • Based on the agreed strategy:
    • if Dependabot: Review and update existing guidance, ensuring it covers the core tech stack of MoJ and DevX repos at least.
    • If Renovate: Develop equivalent guidance from scratch covering the same scope
    • If a migration period is required, develop guidance for both tools covering the transition and migrations steps

Any guidance should cover:

  • Initial setup
  • Recommended configuration (reference templates if needed)
  • Ecosystem coverage
  • Auto-merge vs manual review approaches
  • SLA expectations for PRs
  • Publush to the engineering portal or DevX-documentation site (decision-dependent) under an appropriate section

✅ Definition of Done

  • Existing Dependabot guidance reviewed and updated where required
  • Guidance developed for agreed tool covering all relevant ecosystems
  • Transition guidance developed to cover off migration period
  • Guidance published to DevX documentation site or appropriate
  • Findings shared with wider team where applicable

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the existing Dependabot guidance on the engineering portal and checking the agreed strategy in #231. Document the selected tool's setup, configuration, ecosystem coverage, review approach, and SLA expectations, then publish it to the agreed DevX documentation location and complete the listed definition-of-done checks.

Written by the indexing model from the issue text.

Assessment

Domain
developer-experience, documentation
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.