solid-design-system / solid

Monorepo for Union Investment's Solid Design System.
https://solid-design-system.fe.union-investment.de/docs/
Other
22 stars 4 forks source link

ci: 👷 fix dependabot or switch to renovate #416

Closed karlbaumhauer closed 1 year ago

karlbaumhauer commented 1 year ago

User Story

As a developer of the Solid Design System, I would like to have all dependencies regularly updated and checked for vulnerabilities, so that I am sure our project dependencies are secure and well maintained.

Suggested Solution

As dependabot seems to have issues with pnpm (even thought it is supposed to work), I suggest to quickly have a look into possible fixes and, if it cant be fixed right away, switch to renovate as this works fine in the CMS's monorepo with pnpm.

Environment (GitHub Actions or Azure DevOps)

GitHub

Technical Information

DoR

DoD

mariohamann commented 1 year ago

If this is not going to be fixed soon, we at least should remove Dependabot and all related PRs as this doesn't show our repo in a good shape, bloats our PR overview and our mail inbox. @Vahid1919 @karlbaumhauer

karlbaumhauer commented 1 year ago

@Vahid1919 if you have time and there is nothing left in the milestone to focus on, you could start here... If you need access to the mentioned implementation on azure devops, let me know.