Re: Dependabot pr's

2020-10-16 Thread sebb
On Fri, 16 Oct 2020 at 13:49, Rob Tompkins wrote: > > A thought occurs to me. We are implicitly subscribed to GitHub as committers > on the repo and GitHub sends us emails individually (unless you “un-watch”) > the repo for all of these events. Putting them in a “notifications” list will > like

Re: Dependabot pr's

2020-10-16 Thread Rob Tompkins
A thought occurs to me. We are implicitly subscribed to GitHub as committers on the repo and GitHub sends us emails individually (unless you “un-watch”) the repo for all of these events. Putting them in a “notifications” list will likely duplicate the traffic. I’m not certain how much control we

Re: Dependabot pr's

2020-10-16 Thread Gilles Sadowski
It would be so great to be able to act differently (i.e. redirecting to *different* lists) depending on whether the sender is a bot or a human being. This used to be considered a feature (cf. "robots.txt" for web crawlers). Gilles Le ven. 16 oct. 2020 à 14:36, Rob Tompkins a écrit : > > I’m a +0

Re: Dependabot pr's

2020-10-16 Thread Rob Tompkins
> On Oct 16, 2020, at 6:39 AM, sebb wrote: > > On Fri, 16 Oct 2020 at 07:43, Mark Thomas wrote: >> >>> On 15/10/2020 19:30, Gary Gregory wrote: >>> On Thu, Oct 15, 2020 at 1:57 PM Bernd Eckenfels >>> wrote: >>> Before we do that, I need help. I am considering to ignore or unsubscribe

Re: Dependabot pr's

2020-10-16 Thread Rob Tompkins
I’m a +0.5 to a notifications (GitHub + Jira) list. This seems reasonable to me. -Rob > On Oct 16, 2020, at 2:43 AM, Mark Thomas wrote: > > On 15/10/2020 19:30, Gary Gregory wrote: >>> On Thu, Oct 15, 2020 at 1:57 PM Bernd Eckenfels >>> wrote: >>> >>> Before we do that, I need help. I am

Re: Dependabot pr's

2020-10-16 Thread sebb
On Fri, 16 Oct 2020 at 07:43, Mark Thomas wrote: > > On 15/10/2020 19:30, Gary Gregory wrote: > > On Thu, Oct 15, 2020 at 1:57 PM Bernd Eckenfels > > wrote: > > > >> Before we do that, I need help. I am considering to ignore or unsubscribe > >> the commit mailing list. Which is IMHO not a good th

Re: Dependabot pr's

2020-10-15 Thread Mark Thomas
On 15/10/2020 19:30, Gary Gregory wrote: > On Thu, Oct 15, 2020 at 1:57 PM Bernd Eckenfels > wrote: > >> Before we do that, I need help. I am considering to ignore or unsubscribe >> the commit mailing list. Which is IMHO not a good thing (from the point of >> security reviews). However I cannot k

Re: Dependabot pr's

2020-10-15 Thread Gary Gregory
eate a list called... gh-no...@commons.apache.org? Gary > Gruss > Bernd > -- > http://bernd.eckenfels.net > > Von: John Patrick > Gesendet: Wednesday, October 14, 2020 3:17:22 PM > An: Commons Developers List > Betreff: Dependabot

Re: Dependabot pr's

2020-10-15 Thread Gilles Sadowski
Hi. Le jeu. 15 oct. 2020 à 19:57, Bernd Eckenfels a écrit : > > Before we do that, I need help. I am considering to ignore or unsubscribe the > commit mailing list. Which is IMHO not a good thing (from the point of > security reviews). However I cannot keep up with dependable suggestions (and

Re: Dependabot pr's

2020-10-15 Thread Bernd Eckenfels
: Dependabot pr's to shortcut multiple people telling me not to manually raise pr's to upgrade dependencies, and dependabot is the preferred option for commons to be raising these upgrades, and i should raise a pr to enable dependabot. so... here are all the pr's to enable dependabo

Re: Dependabot pr's

2020-10-15 Thread Gary Gregory
-1 as is: Dependabot is only helpful if you have a GitHub Action build to verify that the update did not break anything. I'm not really paying attention to Travis CI these days but even this list contains components without a GHA or a TCI build. FYI I just added a GHA build to BSF. I have a separa

Dependabot pr's

2020-10-14 Thread John Patrick
to shortcut multiple people telling me not to manually raise pr's to upgrade dependencies, and dependabot is the preferred option for commons to be raising these upgrades, and i should raise a pr to enable dependabot. so... here are all the pr's to enable dependabot on the repo's which lack a depe