Skip to content

Revamp dependency management #2521

@lyuanww

Description

@lyuanww

Description

Currently, we have two dependency management. There is a legacy issue about dependabot and renovate, both creating dependency PRs.

We have decided to remove dependabot for future maintenance.

  1. Remove dependabot
  2. Close all dependabot PRs
  3. Verify renovate PRs and merge, prioritising Update all non-major dependencies except typescript (master) - autoclosed #2437. Currently that PR is not passing CI, and this might be because of a linter dependency being updated.
  4. Look into automerge.

Update the project's dependencies to their latest stable versions to ensure security, performance, and compatibility with modern tooling.

Additional Information

There are also dependencies that are deprecated e.g. types/minimatch.

Metadata

Metadata

Labels

Type

No type

Projects

Status

No status

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions