Skip to content

🛠 Repo: Set up Renovate #5055

@JoshuaKGoldberg

Description

@JoshuaKGoldberg

Tooling Suggestion Checklist

Overview

There are quite a few issues on this repo right now tracking out-of-date packages. We're going to enable Renovate to automatically create PRs to update packages.

Notes from @boneskull:

Looks reasonable. The only thing I’d suggest with the automated tooling (something like Renovate, yeah?) is to have a human in the loop for production dependency upgrades—check them closely. Mocha has been bitten several times due to semver violations in its dependency tree. I would also recommend using https://socket.dev/ as well (should be free for OSS). While Mocha hasn’t been hit by a malicious dep (to my knowledge), historical performance is not a guarantee of future results. 😄

Additional Info

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: repository toolingconcerning ease of contributioncore-teamissues which must be handled by Mocha's core teamstatus: blockedWaiting for something else to be resolvedtype: featureenhancement proposal

    Type

    No type

    Projects

    Status

    Backlog

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions