Skip to content

Scope Bundler Audit to Dependabot Bundler PRs - #3041

Closed
goosys wants to merge 1 commit into
thoughtbot:mainfrom
goosys:chore/scope-bundler-audit-to-dependabot-bundler-prs
Closed

Scope Bundler Audit to Dependabot Bundler PRs#3041
goosys wants to merge 1 commit into
thoughtbot:mainfrom
goosys:chore/scope-bundler-audit-to-dependabot-bundler-prs

Conversation

@goosys

@goosys goosys commented Jul 10, 2026

Copy link
Copy Markdown
Contributor

I’m not sure we need to run this audit on every PR.
Would it make sense to limit it to Dependabot PRs only?

Also, since this workflow checks Bundler dependencies specifically, I additionally scoped it to Dependabot Bundler PRs (dependabot/bundler/*).

What do you think?

@pablobm

pablobm commented Jul 17, 2026

Copy link
Copy Markdown
Collaborator

I think we should disable bundler-audit altogether. This days fails more often than it succeeds, and seeing a failure won't alert us to anything any more. We will continue to merge dependabot PRs at the usual rate, so there's nothing to be gained.

@nickcharlton

Copy link
Copy Markdown
Member

Hm yeah, I agree. I've opened #3059 to just remove it. I'll close this.

nickcharlton added a commit that referenced this pull request Aug 26, 2026
bundle audit isn't helping us that much, so having the CI status
repeatedly failing isn't doing us any favours.

We're using Dependabot to keep up with dependencies otherwise and this
is adequate for this project.

Previously talked about in #3041.
nickcharlton added a commit that referenced this pull request Aug 26, 2026
bundle audit isn't helping us that much, so having the CI status
repeatedly failing isn't doing us any favours.

We're using Dependabot to keep up with dependencies otherwise and this
is adequate for this project.

Previously talked about in #3041.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants