Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependency review in PRs #1045

Open
wmdietl opened this issue Jan 4, 2025 · 0 comments · May be fixed by #1047
Open

Dependency review in PRs #1045

wmdietl opened this issue Jan 4, 2025 · 0 comments · May be fixed by #1047
Assignees

Comments

@wmdietl
Copy link
Member

wmdietl commented Jan 4, 2025

We should also think about whether we really need dependency review as it caused failure/timeout very often. Maybe we should increase the timeout parameter for it?

Please open a PR to look into this. For some PRs, dependency review works flawlessly. For other PRs, dependency review times out, even after multiple restarts. The timeouts never seem to happen once the PRs are merged into master.

What is the point of dependency review on a PR at all? Is it to warn about adding a new high-risk dependency? Or is it only for future dependabot PRs?

Originally posted by @wmdietl in #1042 (comment)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants