sadpandajoe commented on code in PR #44696:
URL: https://github.com/apache/superset/pull/44696#discussion_r4133037148


##########
.github/dependabot.yml:
##########
@@ -9,10 +9,16 @@ updates:
       security:
         applies-to: "security-updates"
         patterns: ["*"]
+      codeql:
+        patterns:
+          - github/codeql-action/*
     cooldown:
       default-days: 7
 
   - package-ecosystem: "npm"
+    # Hack to allow multiple configs for the same ecosystem/directory 
combination
+    # See 
https://github.com/dependabot/dependabot-core/issues/1778#issuecomment-1988140219
+    target-branch: main

Review Comment:
   Dependency updates for `/superset-frontend`, `/superset-embedded-sdk`, 
`/superset-websocket`, and `/docs` would silently stop — `target-branch: main` 
points at a branch that doesn't exist in this repo (default branch is `master`; 
`gh api repos/apache/superset/branches/main` returns 404). Dependabot aborts 
the whole update job when the target branch is missing, and that failure only 
shows up in the repo's Insights → Dependabot tab, not in this PR's CI. Should 
this be `target-branch: master`, or does the multiple-configs workaround need a 
different value here?



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to