Hey JB-

Good question and I think this can become basis for how we manage the tools for 
‘active’ release series going forward.

I think we should keep dependabot running on 5.19.x until the announced 
end-of-active timeframe (End of Feb 27).

We recently had a hiccup where dependent was not running for a while and the 
work to play catchup was really rough. I’d rather merge a few dependabot PRs 
that may-or-not make it into a release vs trying to scramble to address 60 
dependency updates if we decide we need to do a release. 

I suggest we follow the same pattern with 6.3.x. Once we release 6.4.0, we can 
decide on an EOA (end-of-active) timeframe for 6.3.x series and then on that 
date, we disable dependabot, GH workflows for that branch, and update website 
(move the release series to archives, etc).

My $0.02

Thanks,
Matt

> On Sep 10, 2026, at 12:37 PM, Jean-Baptiste Onofré <[email protected]> wrote:
> 
> Hi everyone,
> 
> A while ago, I configured Dependabot to run on the 5.19.x, 6.3.x, and
> main branches.
> 
> Given the recent discussion regarding 5.19.x and the fact that we do
> not plan to make new releases on the activemq-5.19.x branch (unless
> requested by the community), I am wondering if we should keep
> Dependabot enabled for it.
> 
> What are your thoughts?
> 
> Regards,
> JB
> 
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
> For further information, visit: https://activemq.apache.org/contact
> 
> 


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]
For further information, visit: https://activemq.apache.org/contact


Reply via email to