Skip to content

Conversation

@terriko
Copy link
Contributor

@terriko terriko commented Jun 1, 2023

  • Pin ubuntu version in dependency-review job to try to address long queue times
  • Continued experimentation with best config for dependabot to avoid needless cve reports on test files and stop config warnings of duplicates.

The latter may not work, but as there is apparently no way to reliably trigger the config check without merging to main, I guess that's what we have to do for now.

- Pin ubuntu version in dependency-review job to try to address long queue
  times
- Continued experimentation with best config for dependabot to avoid needless
  cve reports on test files *and* stop config warnings of duplicates.

The latter may not work, but as there is apparently no way to reliably trigger
the config check without merging to main, I guess that's what we have to do for
now.

Signed-off-by: Terri Oda <terri.oda@intel.com>
@terriko
Copy link
Contributor Author

terriko commented Jun 1, 2023

This has fixed the dependency check queue time; I won't be able to see the effects of the dependabot fix until this is merged to main so I'm going to do that now.

@terriko terriko merged commit 06cb2e9 into intel:main Jun 1, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant