Hey JB- Good question and I think this can become basis for how we manage the tools for ‘active’ release series going forward.
I think we should keep dependabot running on 5.19.x until the announced end-of-active timeframe (End of Feb 27). We recently had a hiccup where dependent was not running for a while and the work to play catchup was really rough. I’d rather merge a few dependabot PRs that may-or-not make it into a release vs trying to scramble to address 60 dependency updates if we decide we need to do a release. I suggest we follow the same pattern with 6.3.x. Once we release 6.4.0, we can decide on an EOA (end-of-active) timeframe for 6.3.x series and then on that date, we disable dependabot, GH workflows for that branch, and update website (move the release series to archives, etc). My $0.02 Thanks, Matt > On Sep 10, 2026, at 12:37 PM, Jean-Baptiste Onofré <[email protected]> wrote: > > Hi everyone, > > A while ago, I configured Dependabot to run on the 5.19.x, 6.3.x, and > main branches. > > Given the recent discussion regarding 5.19.x and the fact that we do > not plan to make new releases on the activemq-5.19.x branch (unless > requested by the community), I am wondering if we should keep > Dependabot enabled for it. > > What are your thoughts? > > Regards, > JB > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected] > For further information, visit: https://activemq.apache.org/contact > > --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected] For further information, visit: https://activemq.apache.org/contact
