Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
While I've kept the update schedule as "monthly" here, I would suggest that we keep it to a "weekly" basis, as I'll be much faster than Dependabot and will render it useless :P
I think my use case here is about PRs serving as reminders, rather than as updates. But, I can also configure these PRs to get auto-merged if CI passes.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think monthly would be OK.
In my experience, dependabot generates a lot of unwanted notifications, and they are usually not that security critical... in our case we're running a static site, so there are no big security concerns.
As for auto-merge, better not. It makes more sense to auto-merge then check if the page is loading as expected.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yes, I agree. At the current release frequency for JupyterLite and jupyterlite-pyodide-kernel releases, we should be fine with monthly updates.
I agree with this as well.