sadpandajoe commented on code in PR #44696:
URL: https://github.com/apache/superset/pull/44696#discussion_r4139907469


##########
.github/dependabot.yml:
##########
@@ -9,10 +9,16 @@ updates:
       security:
         applies-to: "security-updates"
         patterns: ["*"]
+      codeql:
+        patterns:
+          - github/codeql-action/*
     cooldown:
       default-days: 7
 
   - package-ecosystem: "npm"
+    # Hack to allow multiple configs for the same ecosystem/directory 
combination
+    # See 
https://github.com/dependabot/dependabot-core/issues/1778#issuecomment-1988140219
+    target-branch: master

Review Comment:
   This makes the root npm configuration apply only to version updates, so its 
`security` group no longer governs security updates for these directories. A 
batch of frontend alerts will now arrive as separate PRs rather than the 
configured grouped update. Could the multiple-config workaround avoid 
`target-branch`, or could security-update grouping be configured separately?



##########
.github/dependabot.yml:
##########
@@ -49,7 +55,11 @@ updates:
       # hold comments). Remove this once the proxy code is updated to await
       # the async decompress() API.
       - dependency-name: "simple-zstd"
-    directory: "/superset-frontend/"
+    directories:

Review Comment:
   These directories are still covered by their own npm update entries later in 
the file, so Dependabot now has overlapping npm configurations for the same 
target branch. That can create competing or duplicate version-update PRs for 
the same manifest. Should the dedicated entries be removed or the 
multi-directory entry be limited to non-overlapping paths?



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to