Skip to main content

Dependabot Support

Dependabot can be used to keep Brightspot up to date by automatically submitting pull requests to update any outdated dependencies.

Example Pull Request​

Sample Dependabot PR

Prerequisites​

In order for Dependabot to update Java dependencies managed by the Brightspot Gradle Plugins, version 3.0.0 or later is required.

Conventions​

Resolve # XXX comments​

Comments prefixed with XXX are there for you, the reader of this guide, to review, resolve, and remove before committing changes to the file.

  • ✅ Right: brightspotVersion = 4.5.15.8
  • ❌ Wrong: brightspotVersion = 4.5.15.8 # XXX Copy this version number from the legacy build.gradle
  • 🤡 Extra Wrong: brightspotVersion = 4.5.x # XXX Copy this version number from the legacy build.gradle

In all cases, any comment starting with # XXX must be deleted after satisfying the advice within.

Our recommended configuration employs Dependabot to streamline the deployment of patch releases for:

  • Brightspot
  • Brightspot Go
  • Component-Lib
  • Brightspot Migration Framework
  • Brightspot-Cloud Tomcat Container
  • Brightspot Styleguide
  • Brightspot Gradle Plugins
  • Github Actions Workflows
  • Other third-party dependencies

We do not recommend its use for upgrading major or minor releases of any of the above, as those generally warrant additional manual review.

Setup​

note

This file belongs in /.github/dependabot.yml, not /.github/workflows/dependabot.yml.

dependabot.yml
1
version: 2
2
registries:
3
bsp-cloud-tomcat:
4
type: docker-registry
5
url: __________.dkr.ecr.______.amazonaws.com # XXX Consult the first line of
6
# XXX /etc/container/Dockerfile for this URL.
7
# XXX The account ID and region must match
8
# XXX the URL in the `FROM` line.
9
username: ${{secrets.DEPENDABOT_AWS_ACCESS_KEY_ID}}
10
password: ${{secrets.DEPENDABOT_AWS_SECRET_ACCESS_KEY}}
11
brightspot-artifactory:
12
type: maven-repository
13
url: https://artifactory.psdops.com/public/
14
15
updates:
16
- package-ecosystem: "docker"
17
directory: "/etc/container"
18
registries:
19
- bsp-cloud-tomcat
20
schedule:
21
interval: "daily"
22
ignore:
23
- dependency-name: '*'
24
update-types: ["version-update:semver-major", "version-update:semver-minor"] # ignores tomcat updates for major versions (9 -> 10) and minor versions (8 -> 8.5)
25
commit-message:
26
prefix: "[bsp-tomcat]"
27
28
- package-ecosystem: "gradle"
29
directory: "/"
30
registries:
31
- brightspot-artifactory
32
schedule:
33
interval: "daily"
34
groups:
35
brightspot-dependencies:
36
patterns:
37
- "com.psddev*"
38
- "com.brightspot*"
39
ignore:
40
- dependency-name: "*"
41
update-types: [ "version-update:semver-major", "version-update:semver-minor" ] # ignores updates for major and minor versions
42
43
- package-ecosystem: "npm"
44
directory:
45
directories:
46
- "/frontend/bundles/bundle-default" # XXX If you have multiple frontend bundles, list them here.
47
schedule:
48
interval: "daily"
49
groups:
50
frontend-dependencies:
51
patterns:
52
- "*"
53
ignore:
54
- dependency-name: "*"
55
update-types: [ "version-update:semver-major", "version-update:semver-minor" ] # ignores updates for major and minor versions{% endraw %}
56
57
- package-ecosystem: "github-actions"
58
directory: "/"
59
schedule:
60
interval: "daily"
61
groups:
62
workflow-dependencies:
63
patterns:
64
- "*"

Additional Documentation​

See Github's documentation on Dependabot for more options.

Was this page helpful?

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.