Skip to content

Conversation

@JPeer264
Copy link
Member

A very bold move. Let's make dependabot update all our packages. This was once added in #9752. But I think if we explicilty add an "allow" block, it will automatically ignore others. Which also means when we remove the "allow" block it would also include the ones I just removed.

@JPeer264 JPeer264 self-assigned this Jan 28, 2026
Copy link
Member

@andreiborza andreiborza left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I guess.. but a bit confused because we still had dependabot pr for deps that weren't the ones listed anyway, no?

@github-actions
Copy link
Contributor

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.
⚠️ Warning: Base artifact is not the latest one, because the latest workflow run is not done yet. This may lead to incorrect results. Try to re-run all tests to get up to date results.

Scenario Requests/s % of Baseline Prev. Requests/s Change %
GET Baseline 10,931 - 11,476 -5%
GET With Sentry 1,966 18% 1,941 +1%
GET With Sentry (error only) 7,640 70% 7,519 +2%
POST Baseline 1,269 - 1,305 -3%
POST With Sentry 614 48% 627 -2%
POST With Sentry (error only) 1,123 88% 1,149 -2%
MYSQL Baseline 3,531 - 3,540 -0%
MYSQL With Sentry 533 15% 497 +7%
MYSQL With Sentry (error only) 2,960 84% 3,015 -2%

View base workflow run

@JPeer264
Copy link
Member Author

but a bit confused because we still had dependabot pr for deps that weren't the ones listed anyway, no?

Yes this seems to be a bug in dependabot. I found couple of reports on their repo that listed that.

@JPeer264 JPeer264 merged commit d164ccc into develop Jan 28, 2026
63 checks passed
@JPeer264 JPeer264 deleted the jp/update-all-via-dependabot branch January 28, 2026 11:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants