Skip to content

Revisit GitHub App for quarterly lock-file upgrade PRs #646

Description

@redeboer

Dependabot was adopted as the trigger for lock.yml in #565, closing the earlier GitHub App idea in #346. However, #594 shows that Dependabot is unreliable for several repositories with uv.lock, especially where private repositories are involved.

We should revisit a small organization-owned GitHub App, used from a scheduled workflow, to create quarterly lock-file upgrade PRs across selected ComPWA repositories. This would avoid depending on Dependabot as the trigger while still producing bot-authored PRs with narrow permissions.

Suggested starting point: no webhook server, just GitHub App authentication from a scheduled workflow in ComPWA/.github.

Metadata

Metadata

Assignees

Labels

⚙️ EnhancementImprovements and optimizations of existing features🖱️ DXImprovements to the Developer Experience

Fields

No fields configured for Enhancement.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions