Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[INFRA] Allow only update of dependencies to patch versions #1990

Merged
merged 2 commits into from
May 25, 2022

Conversation

tbouffard
Copy link
Member

In the past, a local 'npm install' run bumped some eslint extensions to minor releases. They included new rules that
broke the lint checks. It was hard to understand why the errors popped suddenly and disturbed developments.
This should not happen with patch updates.

Notes

I started implementing this in dependabot Pull Requests, for instance in #1985.
This PR set the rule to all devDependencies and dependencies that were previously allowed minor updates (^x.y.z).
See https://nodejs.dev/learn/semantic-versioning-using-npm

In the past, a local 'npm install' run bumped some eslint extensions to minor releases. They included new rules that
broke the lint checks. It was hard to understand why the errors popped suddenly and disturbed developments.
This should not happen with patch updates.
@tbouffard tbouffard added the chore Build, CI/CD or repository tasks (issues/PR maintenance, environments, ...) label May 25, 2022
@github-actions
Copy link

github-actions bot commented May 25, 2022

♻️ PR Preview d2df7a2 has been successfully destroyed since this PR has been closed.

🤖 By surge-preview

@github-actions
Copy link

github-actions bot commented May 25, 2022

♻️ PR Preview d2df7a2 has been successfully destroyed since this PR has been closed.

🤖 By surge-preview

@sonarqubecloud
Copy link

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
No Duplication information No Duplication information

@tbouffard tbouffard merged commit ed29567 into master May 25, 2022
@tbouffard tbouffard deleted the infra/only_allow_deps_patch_autoupdate branch May 25, 2022 07:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
chore Build, CI/CD or repository tasks (issues/PR maintenance, environments, ...)
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant