Limiting of Version Leaps #13780
Unanswered
lwbrown42
asked this question in
Code Security
Replies: 1 comment
-
|
A practical way to achieve this today is by controlling the version range directly in your manifest instead of relying on Dependabot to decide the jump size. For example, if you're on 1.2 and want to upgrade only one major at a time, you can set a range like: <3 This forces Dependabot to open a PR only up to the next major. It basically works as a “major-by-major rolling upgrade.” |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
While it's important for dependencies to get upgraded to the latest versions for a variety of reasons, it's very difficult to upgrade and comprehensively test upgrades on packages that are very behind.
Is it possible to configure Dependabot to limit the amount a package can be upgraded in a single PR? For example, if I'm on v1.2 of a package that has up to v6.0 available, can I set Dependabot to be limited to 1 major version per PR, leading to five PRs over time:
This would allow for more comprehensive testing on each PR to make sure that no features are breaking as the package brought up to date.
Beta Was this translation helpful? Give feedback.
All reactions