Skip to content

Explore centralizing Dependabot configuration and shared-workflows SHA updates across keras-team repos #16

Description

@jeffcarp

Context

From @laxmareddyp in keras-team/keras#23768 (comment):

Would Dependabot help solve this? On a related note, our Dependabot configuration is currently duplicated across all our repositories—could we centralize it into shared-workflows to manage it across the entire Keras ecosystem from a single place?

Currently:

  1. .github/dependabot.yml is duplicated across keras-team/keras, keras-team/keras-hub, and other keras-team repositories (with nearly identical github-actions and pip update schedules/groups, plus repo-specific ignore lists).
  2. Caller workflows in keras-team repos pin both uses: keras-team/shared-workflows/.github/workflows/<workflow>.yml@<sha> and with: ref: '<sha>', which must be kept in sync when updating to a new shared-workflows revision.

Goals / Investigation

  • Evaluate whether Dependabot (or an automated sync workflow in shared-workflows) can manage/sync .github/dependabot.yml across keras-team repositories from a single source of truth while preserving repo-specific package ignore entries.
  • Evaluate how to keep uses: ...@<sha> and with: ref: '<sha>' automatically in sync when bumping shared-workflows versions (or whether inputs.ref can be derived/checked automatically).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions