Skip to content

Conversation

@vdemeester
Copy link
Member

Changes

  • Generate the dependabot configuration to handle LTS branches in
    order to prevent release branches dependencies drift and reduce manual
    effort in maintaining per-branch dependency updates
  • For release branches, only bump dependencies on patch versions
  • Enable weekly automated checks with PR creation on changes

Signed-off-by: Vincent Demeester [email protected]

/kind misc
/area automation

Closes #8572

Submitter Checklist

As the author of this PR, please check off the items in this checklist:

  • Has Docs if any changes are user facing, including updates to minimum requirements e.g. Kubernetes version bumps
  • Has Tests included if any functionality added or changed
  • pre-commit Passed
  • Follows the commit message standard
  • Meets the Tekton contributor standards (including functionality, content, code)
  • Has a kind label. You can add one by adding a comment on this PR that contains /kind <type>. Valid types are bug, cleanup, design, documentation, feature, flake, misc, question, tep
  • Release notes block below has been updated with any user facing changes (API changes, bug fixes, changes requiring upgrade notices or deprecation warnings). See some examples of good release notes.
  • Release notes contains the string "action required" if the change requires additional action from users switching to the new release

Release Notes

NONE

@tekton-robot tekton-robot added kind/misc Categorizes issue or PR as a miscellaneuous one. release-note-none Denotes a PR that doesnt merit a release note. labels Nov 28, 2025
@tekton-robot tekton-robot added the area/automation Issues that are related to automation aspects of the website or other projects. label Nov 28, 2025
@tekton-robot
Copy link
Collaborator

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
To complete the pull request process, please ask for approval from vdemeester after the PR has been reviewed.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@tekton-robot tekton-robot added the size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files. label Nov 28, 2025
@vdemeester vdemeester force-pushed the 8572-dependabot-per-branch branch from 57ef204 to aa84d12 Compare November 28, 2025 13:10
- Generate the dependabot configuration to handle LTS branches in
  order to prevent release branches dependencies drift and reduce manual
  effort in maintaining per-branch dependency updates
- For release branches, only bump dependencies on patch versions
- Enable weekly automated checks with PR creation on changes

Signed-off-by: Vincent Demeester <[email protected]>
@vdemeester vdemeester force-pushed the 8572-dependabot-per-branch branch from aa84d12 to 0e0a14c Compare November 28, 2025 13:11
Copy link
Member

@afrittoli afrittoli left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for this. Perhaps for some ecosystems (like GHA), we could setup auto merge if CI passes on release branches, otherwise it will become a lot of work only to approve all the PRs for the various branches 😅

@vdemeester
Copy link
Member Author

Thanks for this. Perhaps for some ecosystems (like GHA), we could setup auto merge if CI passes on release branches, otherwise it will become a lot of work only to approve all the PRs for the various branches 😅

Agreed 👼🏼 But note that we would only update patch dependencies, and it would only do it for the LTSes branches, so it shouldn't be that bad I guess/hope.

Also, we could do it today, by applying the labels (lgtm and approved) directly when creating the pull-request 🧌

@tekton-robot
Copy link
Collaborator

@vdemeester: PR needs rebase.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@tekton-robot tekton-robot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Dec 19, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/automation Issues that are related to automation aspects of the website or other projects. kind/misc Categorizes issue or PR as a miscellaneuous one. needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. release-note-none Denotes a PR that doesnt merit a release note. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files.

Projects

Status: Todo

Development

Successfully merging this pull request may close these issues.

Dependabot for *active* release branches

3 participants