Closed sidvishnoi closed 3 months ago
Name | Link |
---|---|
Latest commit | 34f4fe73038cd3e95b4657edf2b459c17b08f75d |
Latest job logs | Run #9449105029 |
Download | |
Download |
I don't think we should batch all the dependencies updates. This way, we can easily revert the PR if things are not going as planned.
I'm of opinion that PR is the place where we check things are going right or not. Reverts are exceptional. Besides, non-major dependency updates are considered safe enough.
I'm mostly concerned about the noise in git log. We've more dependency commits than actual code commits.
From safety perspective, perhaps we can do certain updates (like open payments package) individually. Best of both?
Closing the PR as most dependencies are merged already, but would like a discussion on reducing the dependency PR noise sometime soon.
Context
Instead of merging separate PRs and adding noise to commit log, maybe we should merge PRs combined weekly? This PR was generated with
ncu
. I've been using this approach on the open-source projects I maintain. We'd let dependabot/renovate generate PRs, but instead of merging each separately, we do this.See also: https://github.com/interledger/web-monetization-extension/pull/270
Changes proposed in this pull request