Skip to content

Conversation

@aaronashby
Copy link
Collaborator

Description

I configured our repository to use Dependabot. Specific details about the agreed-upon workflow (which is subject to change) can be found in DEPENDABOT.md, but essentially, this will allow us to update our dependencies as newer versions become available.

Changes Made

  • Backend changes
  • Frontend changes
  • Database schema changes
  • Configuration updates
  • Other

Testing & Verification

  • Unit tests pass
  • Manual testing completed
  • No breaking changes

Verification Steps:

I forked the repository and added dependabot.yml to that. Dependabot then started making PRs concerning updates to the Dockerfile, npm/yarn packages, and GitHub Actions (also note that since Bew is an automatic assignee, Dependabot was yelling that it couldn't find him in the forked repo, which is to be expected)

Screenshots (if relevant)

Screenshot 2026-01-25 at 11 29 14 AM Screenshot 2026-01-25 at 11 29 44 AM Screenshot 2026-01-25 at 11 31 59 AM

Future Improvements/Notes

Before merging, it would be good to have the entire team agree on a process for reviewing Dependabot's PRs and updating dependencies as needed.

Related Issues

Closes #45

@aaronashby aaronashby linked an issue Jan 25, 2026 that may be closed by this pull request
@thaninbew thaninbew self-requested a review January 25, 2026 17:15
@aaronashby aaronashby requested a review from benjaspet January 25, 2026 17:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Set Up Dependabot

2 participants