Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
6045 commits
Select commit Hold shift + click to select a range
4a81d6a
Bump to Bundler 2.5.5 (#8859)
deivid-rodriguez Feb 22, 2024
1deb6a7
nuget updater command is already space-enabled; allow unsafe executio…
brettfo Feb 22, 2024
fb8697c
Strict type `Dependabot::Clients::BitbucketWithRetries` (#9087)
JamieMagee Feb 22, 2024
716baa8
run the prepare tag step on pull_request_review (#9107)
Nishnha Feb 22, 2024
c2eee76
v0.245.0 (#9094)
dependabot-core-action-automation[bot] Feb 22, 2024
1be91e2
Avoid passing nil url to registry client
bdragon Feb 22, 2024
76cc2c4
Merge branch 'main' into bdragon/iss-9110
bdragon Feb 22, 2024
f72194a
Merge pull request #9111 from dependabot/bdragon/iss-9110
bdragon Feb 22, 2024
88be06e
make DependencySnapshot aware of multiple directories (#8963)
jakecoffman Feb 23, 2024
690b555
Set the dependabot_updater_version docker env from the build arg (#9116)
Nishnha Feb 23, 2024
4229759
Update referenced projects during a run of NuGetUpdater. (#9097)
JoeRobich Feb 23, 2024
c2eb9f7
Strict type `Dependabot::Clients::Bitbucket` (#9113)
JamieMagee Feb 26, 2024
efde250
Strict type `Dependabot::Clients::CodeCommit` (#9121)
JamieMagee Feb 26, 2024
c2788b7
Strict type `Dependabot::Clients::GitHubWithRetries` (#9122)
JamieMagee Feb 26, 2024
10cf389
Strict type `Dependabot::Clients::GitLabWithRetries` (#9129)
JamieMagee Feb 26, 2024
3e975c5
Fetch the cargo config file so we fetch registry definitions (#9109)
pavera Feb 26, 2024
f19696b
Strict type `Dependabot::PullRequestCreator::MessageBuilder` (#9130)
JamieMagee Feb 26, 2024
2adcebb
add more http redirects (#9135)
brettfo Feb 26, 2024
6a32b25
find .nupkg URL without PackageBaseAddress (#9117)
brettfo Feb 26, 2024
71580c0
Strict type `Dependabot::PullRequestUpdater::Gitlab` (#9132)
JamieMagee Feb 26, 2024
64a241e
output job.json at the start of a run (#9133)
jakecoffman Feb 27, 2024
6ddd1cb
Strict type `Dependabot::PullRequestCreator::Azure` (#9131)
JamieMagee Feb 27, 2024
6135d59
Strict type `Dependabot::PullRequestCreator::CodeCommit` (#9141)
JamieMagee Feb 27, 2024
8f91adb
Strict type `Dependabot::PullRequestCreator::Bitbucket` (#9140)
JamieMagee Feb 27, 2024
166a33d
Require `typed: true` for `composer` (#9139)
JamieMagee Feb 27, 2024
09a1c80
Strict type `Dependabot::Elm::Requirement` (#9138)
JamieMagee Feb 27, 2024
7b27803
Strict type `Dependabot::UpdateCheckers::Base` (#8947)
JamieMagee Feb 27, 2024
2a3a059
Enable `Sorbet/TrueSigil` rule in `github_actions` (#9137)
JamieMagee Feb 27, 2024
ff711f9
make test properly fail on malformed path (#9104)
brettfo Feb 27, 2024
3e1e925
don't fail completely if package version cannot be parsed (#9153)
brettfo Feb 28, 2024
6debe84
Bump the sorbet group with 1 update (#9150)
dependabot[bot] Feb 28, 2024
f18ec3b
Strict type `Dependabot::PullRequestCreator::Gitlab`
JamieMagee Feb 28, 2024
26bd19c
Use new Credential class in dry-run script (#9123)
noorul Feb 28, 2024
d880388
Merge branch 'main' into jamiemagee/strict-type-pull-request-creator-…
JamieMagee Feb 28, 2024
4a6efa9
run `nuget restore` if the first update operation failed
brettfo Feb 28, 2024
f259832
Otel is no longer behind a feature flag. Use the in_span method so th…
jpinz Feb 28, 2024
97b4a35
Add the message to the DependencyFileNotFound exception.
jpinz Feb 28, 2024
21b2322
Don't shutdown the otel tracer unless otel is configured.
jpinz Feb 28, 2024
30d5510
Try to fix issue with increment_metric
jpinz Feb 28, 2024
08ecc56
Fix spec test for DependencyFileNotFound
jpinz Feb 28, 2024
b7b545c
Strict type `Dependabot::PullRequestCreator::GitHub`
JamieMagee Feb 27, 2024
b7f14e3
Address PR comments
jpinz Feb 28, 2024
f3ecfca
Update the sorbet type definition of Tracer.in_span
jpinz Feb 28, 2024
2bcbfd6
Fix lint error
jpinz Feb 28, 2024
b486d86
Strict type `Dependabot::PullRequestUpdater::Azure`
JamieMagee Feb 29, 2024
09eaed1
Add a type alias for reviewers
JamieMagee Feb 29, 2024
5bae844
Allow a list of properties to ignore when evaluating MSBuild values.
JoeRobich Feb 29, 2024
eb03831
Strict type `Dependabot::PullRequestUpdater::GitHub`
JamieMagee Feb 29, 2024
caaf994
Merge pull request #9157 from dependabot/dev/brettfo/nuget-restore-be…
bdragon Feb 29, 2024
2e65e49
Merge branch 'main' into jamiemagee/strict-type-pull-request-creator-…
bdragon Feb 29, 2024
1ac6d10
Merge pull request #9154 from dependabot/jamiemagee/strict-type-pull-…
bdragon Feb 29, 2024
75b4812
Merge branch 'main' into jamiemagee/strict-type-pull-request-creator-…
bdragon Feb 29, 2024
614399e
improve nuget v2 handling for non- nuget.org sources
brettfo Feb 29, 2024
facfb6f
Merge branch 'main' into jupinzer/otel_in_span
jpinz Feb 29, 2024
1e9b00f
PR Feedback
JoeRobich Feb 29, 2024
5465b99
Merge branch 'main' into jorobich/ignoreProperties
JoeRobich Feb 29, 2024
da6facb
Merge pull request #9155 from dependabot/jamiemagee/strict-type-pull-…
bdragon Feb 29, 2024
1c6c8d1
Merge branch 'main' into jamiemagee/pull-request-updater-azure
bdragon Feb 29, 2024
1958730
Merge pull request #9163 from dependabot/jamiemagee/pull-request-upda…
bdragon Feb 29, 2024
edc898d
Merge branch 'main' into jamiemagee/strict-type-pull-request-updater-…
bdragon Feb 29, 2024
b982e23
Require `typed: strict` for `common`
JamieMagee Feb 29, 2024
bdc4493
Merge branch 'main' into jupinzer/otel_in_span
JamieMagee Feb 29, 2024
6bca4d7
Merge pull request #9165 from dependabot/jamiemagee/strict-type-pull-…
bdragon Mar 1, 2024
0fe0f29
Merge branch 'main' into jorobich/ignoreProperties
bdragon Mar 1, 2024
fd6205b
Merge branch 'main' into jamiemagee/common-sorbet-strict
JamieMagee Mar 1, 2024
2797f91
Merge pull request #9174 from dependabot/jamiemagee/common-sorbet-strict
jurre Mar 1, 2024
2ca38d2
Require `typed: true` for `docker`
JamieMagee Mar 1, 2024
da08e36
Merge pull request #9175 from dependabot/jamiemagee/docker-typed-true
jurre Mar 1, 2024
b23d75e
Require `typed: true` for `silent`
JamieMagee Mar 1, 2024
ec7d0c7
Merge pull request #9176 from dependabot/jamiemagee/silent-typed-true
jurre Mar 1, 2024
0492308
Merge branch 'main' into jorobich/ignoreProperties
bdragon Mar 1, 2024
148c352
Merge branch 'main' into dev/brettfo/nuget-v2-auth
bdragon Mar 1, 2024
ed47fb8
Merge branch 'main' into jupinzer/otel_in_span
JamieMagee Mar 1, 2024
8f5da96
Merge pull request #9164 from dependabot/jorobich/ignoreProperties
bdragon Mar 1, 2024
d8cf264
Merge branch 'main' into dev/brettfo/nuget-v2-auth
bdragon Mar 1, 2024
11f3f41
Merge branch 'main' into jupinzer/otel_in_span
jpinz Mar 1, 2024
e88ea5e
Merge pull request #9172 from dependabot/dev/brettfo/nuget-v2-auth
bdragon Mar 1, 2024
9699e48
Merge branch 'main' into jupinzer/otel_in_span
jpinz Mar 1, 2024
47a7986
Merge pull request #9158 from dependabot/jupinzer/otel_in_span
bdragon Mar 1, 2024
c9d71b5
v0.246.0
github-actions[bot] Feb 29, 2024
7e39982
Merge pull request #9161 from dependabot/bump-to-v0.246.0
bdragon Mar 1, 2024
7bbda65
Resolve errors from Sorbet `todo.rbi` (#9177)
JamieMagee Mar 2, 2024
945b9c1
Only use credentials which have `registry` configured (#9159)
JamieMagee Mar 2, 2024
9294e76
fix type of requirements_update_strategy (#9197)
jakecoffman Mar 4, 2024
415c020
Require `typed: true` for `cargo` (#9194)
JamieMagee Mar 4, 2024
2ed25a2
Record Sorbet errors with OpenTelemetry (#9202)
JamieMagee Mar 4, 2024
b94ed83
remove tests that are covered by smoke or silent tests (#9205)
jakecoffman Mar 4, 2024
cb43262
use built-in file downloader to get `.nupkg` (#9204)
brettfo Mar 4, 2024
b5ff3af
Strict type most of `github_actions` (#9186)
JamieMagee Mar 4, 2024
be5bbe2
Ensure `T::Set` from `NuGetClient.get_package_versions` (#9180)
JamieMagee Mar 4, 2024
573bddd
build(deps): bump node to v20
yeikel Oct 25, 2023
753c79b
Merge pull request #8275 from yeikel/patch-13
jurre Mar 5, 2024
795dafe
support multi-directory update with no groups (#9148)
jakecoffman Mar 5, 2024
b16a865
Add and configure `rubocop-rspec`
JamieMagee Mar 4, 2024
d232394
Skip if previous_requirements are nil
bdragon Mar 5, 2024
6357b57
Merge pull request #9216 from dependabot/bdragon/iss-9215
bdragon Mar 5, 2024
c2863cf
Merge branch 'main' into jamiemagee/rubocop-rspec
JamieMagee Mar 5, 2024
115b09a
Add handling for nil source_url
bdragon Mar 5, 2024
d583473
Update `NuGet.Client` from `6.8.0.131` to `6.9.1.3`
JamieMagee Mar 5, 2024
02f47fd
Strict type some of `nuget`
JamieMagee Mar 6, 2024
102cf3f
Strict type `nuget` file_fetcher, file_parser, and file_updater classes.
JoeRobich Jan 24, 2024
b35bc43
Bump some files from strict to strong
JoeRobich Mar 6, 2024
55bb734
Bump library/golang in /go_modules (#9226)
dependabot[bot] Mar 6, 2024
1a1b474
Use the API to report errors
landongrindheim Mar 4, 2024
9da3c19
Conform tests to new error reporting
landongrindheim Mar 5, 2024
600d1ae
Gate sending reports to the service
landongrindheim Mar 5, 2024
6a5e0b5
Ensure file fetcher errors are sent to the service
landongrindheim Mar 5, 2024
0520d0b
Update error-routing tests
landongrindheim Mar 5, 2024
1231c0f
Fix Hash key's name
landongrindheim Mar 5, 2024
f7d70ee
Pacify Rubocop
landongrindheim Mar 5, 2024
1494160
fix exception during all-versions-ignored handling (#9214)
jakecoffman Mar 6, 2024
70b40a5
Merge branch 'main' into bdragon/iss-9217
bdragon Mar 6, 2024
5088af7
Merge branch 'main' into jamiemagee/rubocop-rspec
JamieMagee Mar 6, 2024
61c2a2b
Allow `on` as a YAML key
landongrindheim Mar 6, 2024
500dfe3
Merge branch 'main' into route-errors-to-the-api
landongrindheim Mar 6, 2024
d781f4e
Merge pull request #9220 from dependabot/bdragon/iss-9217
bdragon Mar 6, 2024
ce2d187
Merge branch 'main' into jamiemagee/rubocop-rspec
JamieMagee Mar 6, 2024
60c1370
Merge branch 'main' into jamiemagee/update-nuget
JamieMagee Mar 6, 2024
0f9f95b
Merge pull request #9206 from dependabot/jamiemagee/rubocop-rspec
bdragon Mar 6, 2024
8f6dc0a
Merge branch 'main' into jamiemagee/update-nuget
JamieMagee Mar 6, 2024
1d431ba
always directly download nupkg and cache the tfms (#9230)
brettfo Mar 7, 2024
dd20669
report the current version as latest if nothing can be found (#9234)
brettfo Mar 7, 2024
cb8e198
Merge branch 'main' into jamiemagee/update-nuget
JamieMagee Mar 7, 2024
6e9a303
Merge branch 'main' into foster-github-actions-workflow-syntax
JamieMagee Mar 7, 2024
8f06fb0
Merge branch 'main' into joerobich/nugetSorbet
JamieMagee Mar 7, 2024
05e21d7
Merge branch 'main' into route-errors-to-the-api
landongrindheim Mar 7, 2024
9d4a3f2
Localize linter disablement
landongrindheim Mar 7, 2024
600b131
Merge pull request #9208 from dependabot/route-errors-to-the-api
landongrindheim Mar 7, 2024
e19783f
Merge branch 'main' into foster-github-actions-workflow-syntax
landongrindheim Mar 7, 2024
80fdb5a
Merge pull request #9229 from dependabot/foster-github-actions-workfl…
landongrindheim Mar 7, 2024
d055325
Merge branch 'main' into jamiemagee/update-nuget
JamieMagee Mar 7, 2024
61c220e
Merge branch 'main' into joerobich/nugetSorbet
abdulapopoola Mar 7, 2024
081b4e7
Remove reliance on Sentry in bin/* files
landongrindheim Mar 7, 2024
c2b9a98
Post Sorbet errors to the service
landongrindheim Mar 7, 2024
cb6559f
Merge pull request #9222 from dependabot/jamiemagee/update-nuget
bdragon Mar 7, 2024
0edddaf
don't assume the `Include` attribute is present on a `<ProjectReferen…
brettfo Mar 7, 2024
e6b80a6
Merge branch 'main' into joerobich/nugetSorbet
JoeRobich Mar 7, 2024
8b98800
Fix Nuget grouped PR's (#9228)
sebasgomez238 Mar 7, 2024
c334fc7
Merge branch 'main' into joerobich/nugetSorbet
JamieMagee Mar 7, 2024
4c75356
improve robustness of parsing odd-looking version ranges (#9239)
brettfo Mar 7, 2024
ed0c802
Merge branch 'main' into remove-reliance-on-sentry
landongrindheim Mar 7, 2024
0661469
Simplify type parameters for `Gem::Version` (#9232)
JamieMagee Mar 7, 2024
227bbe4
Merge branch 'main' into joerobich/nugetSorbet
JamieMagee Mar 7, 2024
a78590c
Avoid comparison with nil version
bdragon Mar 7, 2024
971d091
Merge pull request #9242 from dependabot/bdragon/iss-9241
bdragon Mar 7, 2024
c5f296d
Merge branch 'main' into joerobich/nugetSorbet
bdragon Mar 7, 2024
d200fb3
Merge pull request #9225 from dependabot/joerobich/nugetSorbet
bdragon Mar 7, 2024
083cad4
Filter out NuGet files where lines were only deleted (#9162)
JamieMagee Mar 8, 2024
6b499fa
Set `branch` for `NuGet.Client` submodule (#9223)
JamieMagee Mar 8, 2024
e5284ce
use safe navigation through resolvable version (#9243)
brettfo Mar 8, 2024
a778269
prevent both directory and directories from being in the job definiti…
jakecoffman Mar 8, 2024
9bd7890
Fix the number of updated directories in a group update (#9240)
Nishnha Mar 8, 2024
9e7d9b3
allow interactive debugging of tests in the updater (#9250)
jakecoffman Mar 8, 2024
135e1bb
Standardize error keys
landongrindheim Mar 8, 2024
6bbcc2b
when resolving MSBuild properties, don't throw if it can't be resolve…
brettfo Mar 11, 2024
eff090a
ensure nupkg zip entry contains a tfm before adding to the list (#9263)
brettfo Mar 11, 2024
809e766
multi-dir rebase of a single dependency (#9212)
jakecoffman Mar 12, 2024
7ee2bd5
Merge branch 'main' into remove-reliance-on-sentry
landongrindheim Mar 12, 2024
b4fb7c3
Merge pull request #9237 from dependabot/remove-reliance-on-sentry
landongrindheim Mar 12, 2024
a07aa22
Use constants to keep keys consistent
landongrindheim Mar 12, 2024
372abcc
Use GROUPS (plural) for consistency
landongrindheim Mar 12, 2024
1fac219
Create stalebot.yml, update contributors to explain its existence (#9…
jonjanego Mar 12, 2024
78c7b48
Update stalebot.yml to bypass yamlint (#9273)
abdulapopoola Mar 12, 2024
95e8e79
Bump the pip-tools group in /python/helpers with 1 update (#9256)
dependabot[bot] Mar 12, 2024
5cb28bf
Send `fingerprint` to distinguish errors
landongrindheim Mar 12, 2024
f16011d
Rely on `T.unsafe` to access `#sentry_context`
landongrindheim Mar 12, 2024
f8648e5
`requirements_update_strategy` is `String` not `Symbol` (#9179)
JamieMagee Mar 13, 2024
d07d710
Type more of `nuget` (#9244)
JamieMagee Mar 13, 2024
c9a5812
Merge branch 'main' into standardize-error-reporting-keys
landongrindheim Mar 13, 2024
ae33ad6
Silence non-file fetching errors
landongrindheim Mar 13, 2024
d3585bb
Allow `files` to be nilable in `solo_strategy` (#9280)
JamieMagee Mar 13, 2024
c355293
update dotnet sdk (#9282)
brettfo Mar 13, 2024
56abecf
Merge branch 'main' into standardize-error-reporting-keys
landongrindheim Mar 13, 2024
e7e5b63
improve update-not-possible logging (#9269)
jakecoffman Mar 13, 2024
d34dfb6
Merge branch 'main' into standardize-error-reporting-keys
landongrindheim Mar 13, 2024
7e6d6f1
Merge pull request #9251 from dependabot/standardize-error-reporting-…
landongrindheim Mar 13, 2024
5b288ba
Merge branch 'main' into stop-reporting-non-file-fetching-errors-to-t…
landongrindheim Mar 13, 2024
5a02df4
Merge pull request #9279 from dependabot/stop-reporting-non-file-fetc…
landongrindheim Mar 13, 2024
fb68913
always recurse submodules when cloning (#9278)
jakecoffman Mar 13, 2024
5485a78
Handle local nuget repositories (#9253)
ryanbrandenburg Mar 14, 2024
6abd87f
Update stalebot.yml (#9285)
jonjanego Mar 14, 2024
8efc1c6
v0.247.0 (#9235)
dependabot-core-action-automation[bot] Mar 14, 2024
65cf578
Strict type `Dependabot::Nuget::UpdateChecker::VersionFinder` (#9284)
JamieMagee Mar 14, 2024
702d4fb
Type more classes (#9275)
ryanbrandenburg Mar 14, 2024
4d467a3
Make `toml` an explicit requirement (#8626)
jeffwidman Mar 14, 2024
ead6e1b
Update stalebot.yml
jonjanego Mar 14, 2024
ebfa520
Merge pull request #9295 from dependabot/jonjanego-patch-1
jonjanego Mar 14, 2024
3e33aee
Update stalebot.yml
jonjanego Mar 14, 2024
3002581
Merge pull request #9298 from dependabot/jonjanego-patch-1
jonjanego Mar 14, 2024
d798a74
Update stalebot.yml
jonjanego Mar 15, 2024
d710546
make dependency file not found message more specific (#9294)
brettfo Mar 15, 2024
e25ccee
Strict type some more `nuget` (#9293)
JamieMagee Mar 15, 2024
5009f68
Merge branch 'main' into jonjanego-patch-1
jonjanego Mar 15, 2024
8a387f9
Merge pull request #9302 from dependabot/jonjanego-patch-1
jonjanego Mar 15, 2024
6fd3193
Bump the sorbet group with 1 update (#9274)
dependabot[bot] Mar 15, 2024
a30e864
Create issue-labeler.yml (#9305)
abdulapopoola Mar 15, 2024
670c1d8
Create add-to-core-project.yml (#9307)
abdulapopoola Mar 15, 2024
b056893
Update add-to-core-project.yml (#9310)
abdulapopoola Mar 15, 2024
614a6b3
Update PNPM to 8.15.5 (#9320)
abdulapopoola Mar 18, 2024
7b40f08
report discovered dependencies and requirement metadata (#9303)
brettfo Mar 19, 2024
522f500
chore(python): target latest python versions 3.12.2, 3.11.8 (#9328)
sileht Mar 20, 2024
c7b16a1
Switch to offical GitHub action for managing app tokens (#9340)
jeffwidman Mar 21, 2024
d1e4333
v0.248.0 (#9339)
dependabot-core-action-automation[bot] Mar 21, 2024
4a83645
Set `Style/AccessorGrouping` to `separated` (#9336)
JamieMagee Mar 22, 2024
1b179eb
Start strict typing `gradle` (#9346)
JamieMagee Mar 22, 2024
569d4ef
Cover parts of `go_modules` code with Sorbet (#9338)
ByAgenT Mar 22, 2024
d2b94f6
Strict type more of NuGet (#9337)
JamieMagee Mar 22, 2024
84f3685
Fix Invalid .yarnrc.yml File due to Missing Double Quotes (#9322)
honeyankit Mar 22, 2024
384ce3b
Switch from `pipfile` to `plette` lib (#8627)
jeffwidman Mar 22, 2024
1943a74
`@target_version` can be `String` or `Dependabot::Nuget::Version` (#9…
JamieMagee Mar 25, 2024
db95024
Bump the poetry group in /python/helpers with 2 updates (#9291)
dependabot[bot] Mar 25, 2024
3b1250b
Support Poetry non-package mode (#9323)
onlined Mar 25, 2024
634b2fa
add and update tests around group update failures (#9363)
jakecoffman Mar 25, 2024
b759529
swap language when closing group refresh PR to be less specific (#9371)
jakecoffman Mar 26, 2024
298929c
fix: parse plugin artifactItem dependencies (#9313)
yeikel Mar 26, 2024
85d18d5
Return early if method arguments are nil
bdragon Mar 26, 2024
67dc6ec
Add a test
bdragon Mar 26, 2024
5d769a9
Merge pull request #9366 from dependabot/bdragon/fix-nil-err
bdragon Mar 26, 2024
cd03173
only report dependencies from project files that have a target framew…
brettfo Mar 26, 2024
f364ade
Fix CodeCommit 'fetch_repo_contents' strict type enforcement from Aws…
dwc0011 Mar 26, 2024
e05bd19
test for exclude patterns (#9377)
jakecoffman Mar 27, 2024
db2cd23
sorbet: package_version may be nil (#9365)
bdragon Mar 27, 2024
32aa57a
don't allow `global.json` from repo to affect MSBuild discovery (#9374)
brettfo Mar 27, 2024
3a27e09
Add `require 'sorbet-runtime'` where missing (#9379)
JamieMagee Mar 27, 2024
9f67b86
honor `packageSourceMapping` from `NuGet.Config` (#9381)
brettfo Mar 28, 2024
d37c8f7
Avoid including `group` in PR titles twice
jurre Mar 28, 2024
64b114a
Merge pull request #9384 from dependabot/jurre/fix-group-name-in-pr-t…
jurre Mar 28, 2024
553f7c7
v0.249.0
github-actions[bot] Mar 28, 2024
4157975
Merge pull request #9382 from dependabot/bump-to-v0.249.0
landongrindheim Mar 28, 2024
f95f1da
Update npm sorbet types (#9343)
ryanbrandenburg Mar 29, 2024
fe6b41e
don't fail loading build files that don't exist (#9385)
brettfo Mar 31, 2024
866b76f
remove unused boolean from input (#9401)
jakecoffman Apr 1, 2024
736d9bb
fix really long branch names (#9410)
jakecoffman Apr 2, 2024
ffd44ca
v0.250.0 (#9412)
dependabot-core-action-automation[bot] Apr 2, 2024
b702af6
Handle requests for review from dependabot
landongrindheim Apr 1, 2024
30b8dd0
Merge pull request #9398 from dependabot/handle-requesting-reviews-fr…
landongrindheim Apr 2, 2024
1fc9a86
only report dependencies whose version numbers can be resolved (#9387)
brettfo Apr 2, 2024
1d7be41
Prevent comparison of Integer with String
bdragon Mar 26, 2024
428caf1
Table doesn't properly end for multi-directory GSU (#9364)
honeyankit Apr 3, 2024
ffc8546
allow flamegraph gathering (#9423)
jakecoffman Apr 3, 2024
4784dc0
remove redundant parsing of original files (#9424)
jakecoffman Apr 3, 2024
7cc526c
Add a test
bdragon Apr 3, 2024
9c9f673
Merge branch 'main' into bdragon/fix-argument-err
bdragon Apr 3, 2024
432c793
Merge pull request #9367 from dependabot/bdragon/fix-argument-err
bdragon Apr 3, 2024
d2e6b5d
sorbet: ensure non-nil value before calling T.must
bdragon Apr 3, 2024
36e67c6
Merge pull request #9428 from dependabot/bdragon/iss-9325
bdragon Apr 4, 2024
1425ec2
fix multi-version ecosystem security vulnerability failure (#9434)
jakecoffman Apr 4, 2024
d53fce0
If only 1 dep in group is updated, use solo title (#9416)
pavera Apr 4, 2024
005dd73
Better support around bundler changelogs (#9429)
Nishnha Apr 4, 2024
31ef475
Merge remote-tracking branch
shivamhelp Apr 5, 2024
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
6 changes: 6 additions & 0 deletions .codespellrc
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
[codespell]
skip = .git,*.pdf,*.svg,gems,index,fixtures,CHANGELOG_ARCHIVE_*,yarn.lock
ignore-regex = \bsha512-[^"]*|ENV\["ROUGE"\]|\b(com\.google\.errorprone)\b|\bto(_not)? include .*versio"|https://\S*
# some modules, parts of regexes, and variable names to ignore, some
# misspellings in fixtures/external responses we do not own
ignore-words-list = caf,bu,nwo,nd,kernal,crate,unparseable,couldn,defintions
11 changes: 11 additions & 0 deletions .devcontainer/Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
# See here for image contents: https://github.com/microsoft/vscode-dev-containers/tree/v0.245.2/containers/ubuntu/.devcontainer/base.Dockerfile

# [Choice] Ubuntu version (use ubuntu-22.04 or ubuntu-18.04 on local arm64/Apple Silicon): ubuntu-22.04, ubuntu-20.04, ubuntu-18.04
ARG VARIANT="jammy"
FROM mcr.microsoft.com/vscode/devcontainers/base:0-${VARIANT}

# [Optional] Uncomment this section to install additional OS packages.
# RUN apt-get update && export DEBIAN_FRONTEND=noninteractive \
# && apt-get -y install --no-install-recommends <your-package-list-here>


106 changes: 106 additions & 0 deletions .devcontainer/core-dev/devcontainer.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,106 @@
{
"name": "core-dev",
"build": {
"dockerfile": "../../Dockerfile.development",
"cacheFrom": "ghcr.io/dependabot/dependabot-updater-core"
},

"workspaceFolder": "/home/dependabot/dependabot-core",

"runArgs": [
"-u", "dependabot",
"-e", "LOCAL_GITHUB_ACCESS_TOKEN=${env:LOCAL_GITHUB_ACCESS_TOKEN}",
"-e", "LOCAL_CONFIG_VARIABLES=${env:LOCAL_CONFIG_VARIABLES}",

"-v", "${localWorkspaceFolder}/.vscode:/home/dependabot/dependabot-core/.vscode",
"-v", "${localWorkspaceFolder}/.gitignore:/home/dependabot/dependabot-core/.gitignore",
"-v", "${localWorkspaceFolder}/.rubocop.yml:/home/dependabot/dependabot-core/.rubocop.yml",
"-v", "${localWorkspaceFolder}/bin:/home/dependabot/dependabot-core/bin",
"-v", "${localWorkspaceFolder}/common/dependabot-common.gemspec:/home/dependabot/dependabot-core/common/dependabot-common.gemspec",
"-v", "${localWorkspaceFolder}/common/bin:/home/dependabot/dependabot-core/common/bin",
"-v", "${localWorkspaceFolder}/common/lib:/home/dependabot/dependabot-core/common/lib",
"-v", "${localWorkspaceFolder}/common/spec:/home/dependabot/dependabot-core/common/spec",
"-v", "${localWorkspaceFolder}/bundler/dependabot-bundler.gemspec:/home/dependabot/dependabot-core/bundler/dependabot-bundler.gemspec",
"-v", "${localWorkspaceFolder}/bundler/helpers:/home/dependabot/dependabot-core/bundler/helpers",
"-v", "${localWorkspaceFolder}/bundler/lib:/home/dependabot/dependabot-core/bundler/lib",
"-v", "${localWorkspaceFolder}/bundler/spec:/home/dependabot/dependabot-core/bundler/spec",
"-v", "${localWorkspaceFolder}/cargo/dependabot-cargo.gemspec:/home/dependabot/dependabot-core/cargo/dependabot-cargo.gemspec",
"-v", "${localWorkspaceFolder}/cargo/lib:/home/dependabot/dependabot-core/cargo/lib",
"-v", "${localWorkspaceFolder}/cargo/spec:/home/dependabot/dependabot-core/cargo/spec",
"-v", "${localWorkspaceFolder}/composer/dependabot-composer.gemspec:/home/dependabot/dependabot-core/composer/dependabot-composer.gemspec",
"-v", "${localWorkspaceFolder}/composer/lib:/home/dependabot/dependabot-core/composer/lib",
"-v", "${localWorkspaceFolder}/composer/spec:/home/dependabot/dependabot-core/composer/spec",
"-v", "${localWorkspaceFolder}/docker/dependabot-docker.gemspec:/home/dependabot/dependabot-core/docker/dependabot-docker.gemspec",
"-v", "${localWorkspaceFolder}/docker/lib:/home/dependabot/dependabot-core/docker/lib",
"-v", "${localWorkspaceFolder}/docker/spec:/home/dependabot/dependabot-core/docker/spec",
"-v", "${localWorkspaceFolder}/elm/dependabot-elm.gemspec:/home/dependabot/dependabot-core/elm/dependabot-elm.gemspec",
"-v", "${localWorkspaceFolder}/elm/lib:/home/dependabot/dependabot-core/elm/lib",
"-v", "${localWorkspaceFolder}/elm/spec:/home/dependabot/dependabot-core/elm/spec",
"-v", "${localWorkspaceFolder}/git_submodules/dependabot-git_submodules.gemspec:/home/dependabot/dependabot-core/git_submodules/dependabot-git_submodules.gemspec",
"-v", "${localWorkspaceFolder}/git_submodules/lib:/home/dependabot/dependabot-core/git_submodules/lib",
"-v", "${localWorkspaceFolder}/git_submodules/spec:/home/dependabot/dependabot-core/git_submodules/spec",
"-v", "${localWorkspaceFolder}/github_actions/dependabot-github_actions.gemspec:/home/dependabot/dependabot-core/github_actions/dependabot-github_actions.gemspec",
"-v", "${localWorkspaceFolder}/github_actions/lib:/home/dependabot/dependabot-core/github_actions/lib",
"-v", "${localWorkspaceFolder}/github_actions/spec:/home/dependabot/dependabot-core/github_actions/spec",
"-v", "${localWorkspaceFolder}/go_modules/dependabot-go_modules.gemspec:/home/dependabot/dependabot-core/go_modules/dependabot-go_modules.gemspec",
"-v", "${localWorkspaceFolder}/go_modules/lib:/home/dependabot/dependabot-core/go_modules/lib",
"-v", "${localWorkspaceFolder}/go_modules/spec:/home/dependabot/dependabot-core/go_modules/spec",
"-v", "${localWorkspaceFolder}/gradle/dependabot-gradle.gemspec:/home/dependabot/dependabot-core/gradle/dependabot-gradle.gemspec",
"-v", "${localWorkspaceFolder}/gradle/lib:/home/dependabot/dependabot-core/gradle/lib",
"-v", "${localWorkspaceFolder}/gradle/spec:/home/dependabot/dependabot-core/gradle/spec",
"-v", "${localWorkspaceFolder}/hex/dependabot-hex.gemspec:/home/dependabot/dependabot-core/hex/dependabot-hex.gemspec",
"-v", "${localWorkspaceFolder}/hex/lib:/home/dependabot/dependabot-core/hex/lib",
"-v", "${localWorkspaceFolder}/hex/spec:/home/dependabot/dependabot-core/hex/spec",
"-v", "${localWorkspaceFolder}/maven/dependabot-maven.gemspec:/home/dependabot/dependabot-core/maven/dependabot-maven.gemspec",
"-v", "${localWorkspaceFolder}/maven/lib:/home/dependabot/dependabot-core/maven/lib",
"-v", "${localWorkspaceFolder}/maven/spec:/home/dependabot/dependabot-core/maven/spec",
"-v", "${localWorkspaceFolder}/npm_and_yarn/dependabot-npm_and_yarn.gemspec:/home/dependabot/dependabot-core/npm_and_yarn/dependabot-npm_and_yarn.gemspec",
"-v", "${localWorkspaceFolder}/npm_and_yarn/lib:/home/dependabot/dependabot-core/npm_and_yarn/lib",
"-v", "${localWorkspaceFolder}/npm_and_yarn/spec:/home/dependabot/dependabot-core/npm_and_yarn/spec",
"-v", "${localWorkspaceFolder}/nuget/dependabot-nuget.gemspec:/home/dependabot/dependabot-core/nuget/dependabot-nuget.gemspec",
"-v", "${localWorkspaceFolder}/nuget/lib:/home/dependabot/dependabot-core/nuget/lib",
"-v", "${localWorkspaceFolder}/nuget/spec:/home/dependabot/dependabot-core/nuget/spec",
"-v", "${localWorkspaceFolder}/pub/dependabot-pub.gemspec:/home/dependabot/dependabot-core/pub/dependabot-pub.gemspec",
"-v", "${localWorkspaceFolder}/pub/lib:/home/dependabot/dependabot-core/pub/lib",
"-v", "${localWorkspaceFolder}/pub/spec:/home/dependabot/dependabot-core/pub/spec",
"-v", "${localWorkspaceFolder}/python/dependabot-python.gemspec:/home/dependabot/dependabot-core/python/dependabot-python.gemspec",
"-v", "${localWorkspaceFolder}/python/lib:/home/dependabot/dependabot-core/python/lib",
"-v", "${localWorkspaceFolder}/python/spec:/home/dependabot/dependabot-core/python/spec",
"-v", "${localWorkspaceFolder}/swift/dependabot-swift.gemspec:/home/dependabot/dependabot-core/swift/dependabot-swift.gemspec",
"-v", "${localWorkspaceFolder}/swift/lib:/home/dependabot/dependabot-core/swift/lib",
"-v", "${localWorkspaceFolder}/swift/spec:/home/dependabot/dependabot-core/swift/spec",
"-v", "${localWorkspaceFolder}/terraform/dependabot-terraform.gemspec:/home/dependabot/dependabot-core/terraform/dependabot-terraform.gemspec",
"-v", "${localWorkspaceFolder}/terraform/lib:/home/dependabot/dependabot-core/terraform/lib",
"-v", "${localWorkspaceFolder}/terraform/spec:/home/dependabot/dependabot-core/terraform/spec",
"-v", "${localWorkspaceFolder}/omnibus/Gemfile:/home/dependabot/dependabot-core/omnibus/Gemfile",
"-v", "${localWorkspaceFolder}/omnibus/dependabot-omnibus.gemspec:/home/dependabot/dependabot-core/omnibus/dependabot-omnibus.gemspec",
"-v", "${localWorkspaceFolder}/omnibus/lib:/home/dependabot/dependabot-core/omnibus/lib",

"--cap-add=SYS_PTRACE", "--security-opt", "seccomp=unconfined"
],
"customizations": {
"vscode": {
"extensions": [
"ms-vscode-remote.remote-containers",
"rubocop.vscode-rubocop",
"shopify.ruby-extensions-pack"
],
"settings": {
"[ruby]": {
"editor.defaultFormatter": "Shopify.ruby-lsp",
"editor.formatOnSave": true,
"editor.formatOnType": true,
"editor.insertSpaces": true,
"editor.rulers": [120],
"editor.semanticHighlighting.enabled": true,
"editor.tabSize": 2,
"files.insertFinalNewline": true,
"files.trimFinalNewlines": true,
"files.trimTrailingWhitespace": true
},
"rubocop.autocorrect": true,
"sorbet.enabled": true
}
}
}
}
Loading