sadpandajoe commented on code in PR #44696:
URL: https://github.com/apache/superset/pull/44696#discussion_r4133037148
##########
.github/dependabot.yml:
##########
@@ -9,10 +9,16 @@ updates:
security:
applies-to: "security-updates"
patterns: ["*"]
+ codeql:
+ patterns:
+ - github/codeql-action/*
cooldown:
default-days: 7
- package-ecosystem: "npm"
+ # Hack to allow multiple configs for the same ecosystem/directory
combination
+ # See
https://github.com/dependabot/dependabot-core/issues/1778#issuecomment-1988140219
+ target-branch: main
Review Comment:
Dependency updates for `/superset-frontend`, `/superset-embedded-sdk`,
`/superset-websocket`, and `/docs` would silently stop — `target-branch: main`
points at a branch that doesn't exist in this repo (default branch is `master`;
`gh api repos/apache/superset/branches/main` returns 404). Dependabot aborts
the whole update job when the target branch is missing, and that failure only
shows up in the repo's Insights → Dependabot tab, not in this PR's CI. Should
this be `target-branch: master`, or does the multiple-configs workaround need a
different value here?
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]