Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot does not scan for versions in versions.properties #3782

Closed
saratvemulapalli opened this issue Jul 5, 2022 · 1 comment · Fixed by cwperks/OpenSearch#203, cwperks/OpenSearch#206 or #16284
Labels
CI CI related cicd enhancement Enhancement or improvement to existing feature or request feature New feature or request v2.19.0 Issues and PRs related to version 2.19.0 v3.0.0 Issues and PRs related to version 3.0.0

Comments

@saratvemulapalli
Copy link
Member

saratvemulapalli commented Jul 5, 2022

Is your feature request related to a problem? Please describe.
Coming from: #3772 (comment)
Dependabot does a great job of automatically upgrading dependent libraries while checking CVE databases.

For OpenSearch we use versions.properties[1] as a version catalog for all gradle projects within the repository.
Dependabot workflow does not support scanning through this catalog file of versions.

Describe the solution you'd like
Dependabot support for dependencies listed in versions.properties.

[1] https://github.com/opensearch-project/OpenSearch/blob/main/buildSrc/version.properties

@saratvemulapalli saratvemulapalli added enhancement Enhancement or improvement to existing feature or request untriaged labels Jul 5, 2022
@reta reta mentioned this issue Jul 8, 2022
5 tasks
@mch2 mch2 added CI CI related feature New feature or request cicd and removed untriaged labels Jul 11, 2022
@reta reta mentioned this issue Aug 26, 2022
6 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment