Title: How should we be using dependabot in this repo? · Issue #223 · python/pyperformance · GitHub
Open Graph Title: How should we be using dependabot in this repo? · Issue #223 · python/pyperformance
X Title: How should we be using dependabot in this repo? · Issue #223 · python/pyperformance
Description: I noticed a few dependabot PRs in this repo, such as this one that upgrade dependencies of specific benchmarks. While in general, I think this is good practice, for a benchmark suite, I think we'd want to upgrade these dependencies as in...
Open Graph Description: I noticed a few dependabot PRs in this repo, such as this one that upgrade dependencies of specific benchmarks. While in general, I think this is good practice, for a benchmark suite, I think we'd ...
X Description: I noticed a few dependabot PRs in this repo, such as this one that upgrade dependencies of specific benchmarks. While in general, I think this is good practice, for a benchmark suite, I think we...
Opengraph URL: https://github.com/python/pyperformance/issues/223
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"How should we be using dependabot in this repo?","articleBody":"I noticed a few dependabot PRs in this repo, such as [this one](https://github.com/python/pyperformance/pull/220) that upgrade dependencies of specific benchmarks. While in general, I think this is good practice, for a benchmark suite, I think we'd want to upgrade these dependencies as infrequently as possible to keep benchmarking results comparable with one another (and not have to always rerun baselines). Occasionally we are forced to upgrade, for example to get compatibility with a new version of CPython, but that should be deliberate.\r\n\r\n(It's possible there is a security counterargument to be made, but I'm not a security expert and I don't know specifically whether that matters or not).\r\n\r\nWould it make sense to update the dependabot config to only look at the top-level dependencies of `pyperformance` itself rather than the dependencies of specific benchmarks?\r\n","author":{"url":"https://github.com/mdboom","@type":"Person","name":"mdboom"},"datePublished":"2022-07-07T15:18:18.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":10},"url":"https://github.com/223/pyperformance/issues/223"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:a2bc920a-14eb-d3da-1466-457b14be4e1c |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | C5DA:281234:3E9FC1:572A0E:696A0B27 |
| html-safe-nonce | 6349f171779272388f5b37c2ab35ae2a20204edb0631720d506038bf6fe7961e |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJDNURBOjI4MTIzNDozRTlGQzE6NTcyQTBFOjY5NkEwQjI3IiwidmlzaXRvcl9pZCI6IjMyNTc5MDc0MzIyMzQwMjc4MTUiLCJyZWdpb25fZWRnZSI6ImlhZCIsInJlZ2lvbl9yZW5kZXIiOiJpYWQifQ== |
| visitor-hmac | 021f8d4455e4a6c056d937bfda74fa11c95342ec4dd126622a66b7955ad7f6bf |
| hovercard-subject-tag | issue:1297626026 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/python/pyperformance/223/issue_layout |
| twitter:image | https://opengraph.githubassets.com/85fe58a46a9bd4ebcf1aa06475172280467822e2eefb87a8ac83780d32554428/python/pyperformance/issues/223 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/85fe58a46a9bd4ebcf1aa06475172280467822e2eefb87a8ac83780d32554428/python/pyperformance/issues/223 |
| og:image:alt | I noticed a few dependabot PRs in this repo, such as this one that upgrade dependencies of specific benchmarks. While in general, I think this is good practice, for a benchmark suite, I think we'd ... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | mdboom |
| hostname | github.com |
| expected-hostname | github.com |
| None | 699227a00bbb7fe1eec276d2ae1c3a93068bc5ba483bd9dc4b2a27a8f4f2f595 |
| turbo-cache-control | no-preview |
| go-import | github.com/python/pyperformance git https://github.com/python/pyperformance.git |
| octolytics-dimension-user_id | 1525981 |
| octolytics-dimension-user_login | python |
| octolytics-dimension-repository_id | 65949828 |
| octolytics-dimension-repository_nwo | python/pyperformance |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 65949828 |
| octolytics-dimension-repository_network_root_nwo | python/pyperformance |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 7266b2d935baa1c6474b16dd9feaa5ca30607261 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width