opensafely-core / opensafely-core/opensafely-cli

Dev requirements are not being updated

Open
#306 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

deck-scrubbing
Dominant language
Python
Stars
2
Forks
5
Avg merge
2d 1h
Merged PRs (30d)
4

Description

  • Dependabot isn't configured.
  • Also Dependabot doesn't work with Python 3.8, even if configured.

Should we use the update-dependencies action instead?

Edit: To avoid errors from Dependabot security updates, we've disabled the "Dependabot security updates" option for this repository, for now. It was only checking for dev requirements.

If we fix #280 and switch back to Dependabot, we should re-enable Dependabot security updates.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files or tests are named. Review the repository's current dependency-update configuration and issue #280 first, then determine whether Dependabot or the update-dependencies action supports the project's Python version and dev requirements. Done means dev requirements update reliably and the security-update setting is handled as specified.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions, python
Domain
ci-cd, devops
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
32/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.