Context
From @laxmareddyp in keras-team/keras#23768 (comment):
Would Dependabot help solve this? On a related note, our Dependabot configuration is currently duplicated across all our repositories—could we centralize it into shared-workflows to manage it across the entire Keras ecosystem from a single place?
Currently:
.github/dependabot.yml is duplicated across keras-team/keras, keras-team/keras-hub, and other keras-team repositories (with nearly identical github-actions and pip update schedules/groups, plus repo-specific ignore lists).
- Caller workflows in
keras-team repos pin both uses: keras-team/shared-workflows/.github/workflows/<workflow>.yml@<sha> and with: ref: '<sha>', which must be kept in sync when updating to a new shared-workflows revision.
Goals / Investigation
- Evaluate whether Dependabot (or an automated sync workflow in
shared-workflows) can manage/sync .github/dependabot.yml across keras-team repositories from a single source of truth while preserving repo-specific package ignore entries.
- Evaluate how to keep
uses: ...@<sha> and with: ref: '<sha>' automatically in sync when bumping shared-workflows versions (or whether inputs.ref can be derived/checked automatically).
Context
From @laxmareddyp in keras-team/keras#23768 (comment):
Currently:
.github/dependabot.ymlis duplicated acrosskeras-team/keras,keras-team/keras-hub, and otherkeras-teamrepositories (with nearly identicalgithub-actionsandpipupdate schedules/groups, plus repo-specificignorelists).keras-teamrepos pin bothuses: keras-team/shared-workflows/.github/workflows/<workflow>.yml@<sha>andwith: ref: '<sha>', which must be kept in sync when updating to a newshared-workflowsrevision.Goals / Investigation
shared-workflows) can manage/sync.github/dependabot.ymlacrosskeras-teamrepositories from a single source of truth while preserving repo-specific packageignoreentries.uses: ...@<sha>andwith: ref: '<sha>'automatically in sync when bumpingshared-workflowsversions (or whetherinputs.refcan be derived/checked automatically).