Amp-wp: Switch from Renovate to Dependabot for dependency updates

Created on 10 Jun 2020  路  5Comments  路  Source: ampproject/amp-wp

Feature description

We've seen that Dependabot does better at updating PHP dependencies in the composer.json.

Also, now that we have a GitHub action which does ZIP builds for PRs, this is restricted to PRs not coming from forks, which is another benefit that Dependabot provides.

Therefore, we should decommission Renovate and switch instead to Dependabot.


_Do not alter or remove anything below. The following sections will be managed by moderators only._

Acceptance criteria

Implementation brief

QA testing instructions

Demo

Changelog entry

Infrastructure P1 Core dependencies

Most helpful comment

Thanks to @kristoferbaxter and @rsimha, dependabot is now in the allowlist for the CLA.

The check is passing:

image

https://github.com/ampproject/amp-wp/pulls/app%2Fdependabot-preview

All 5 comments

FYI: Renovate has now been disabled for amp-wp.

@schlessera It has also been disabled for amp-toolbox-php.

Please let me know if you see any issues following disable.

Only outstanding issue is needing to add dependabot-preview to the CLAassistant allowlist:

claassistant

^ Coincidentally just asked about this in the #wg-infra Slack channel.

Thanks to @kristoferbaxter and @rsimha, dependabot is now in the allowlist for the CLA.

The check is passing:

image

https://github.com/ampproject/amp-wp/pulls/app%2Fdependabot-preview

Was this page helpful?
0 / 5 - 0 ratings

Related issues

miina picture miina  路  5Comments

maciejmackowiak picture maciejmackowiak  路  5Comments

westonruter picture westonruter  路  5Comments

GitaStreet picture GitaStreet  路  4Comments

swissspidy picture swissspidy  路  4Comments