You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This issue is not about shipping the quickest or easiest solution.
Take time to research the problem, explore alternatives, discuss the approach with @Norbiros and the team, and implement a solution you can confidently defend in code review.
Task
Configure automatic dependency updates for npm packages, GitHub Actions, and Dockerfiles. Our preferred tool for this is Mend Renovate, since it has many useful features and integrations.
Possible considerations:
Is Renovate the best choice?
Should we use .json, .json5, or .jsonc?
Can we improve security so we do not miss important updates, while still keeping a minimum release age of 1 day?
What is the best strategy: pinning, bumping, or something else?
Create a unified configuration, preferably in .github, so we can reuse the same config across all repositories, similar to how Nuxt does it. Reusing configuration is better than copying it over and over.
Configure all projects to use pinned GitHub Actions versions and make this required at the organization level.
Other, pre-existing solutions
Do not copy this 1:1. The goal is to find something better and learn from the process.
Tip
This issue is not about shipping the quickest or easiest solution.
Take time to research the problem, explore alternatives, discuss the approach with @Norbiros and the team, and implement a solution you can confidently defend in code review.
Task
Configure automatic dependency updates for npm packages, GitHub Actions, and Dockerfiles. Our preferred tool for this is Mend Renovate, since it has many useful features and integrations.
Possible considerations:
.json,.json5, or.jsonc?Taking it a step further:
.github, so we can reuse the same config across all repositories, similar to how Nuxt does it. Reusing configuration is better than copying it over and over.Other, pre-existing solutions
Do not copy this 1:1. The goal is to find something better and learn from the process.
From
motoq: