ci: Ignore multiple images major versions bump - #4466
Conversation
5a8bc83 to
1a462f2
Compare
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Want reviews to match your repository better? Bugbot Learning can learn team-specific rules from PR activity. A team admin can enable Learning in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 1a462f2. Configure here.
| - ">=2" | ||
| - dependency-name: chrislusf/seaweedfs | ||
| versions: | ||
| - ">=5" |
There was a problem hiding this comment.
SeaweedFS ignore likely ineffective
Low Severity
The new chrislusf/seaweedfs ignore may not block major bumps. That image is pinned with a digest in docker-compose.yml, and Dependabot still does not honor versions ignores for digest-pinned compose images, so >=5 updates can keep opening.
Reviewed by Cursor Bugbot for commit 1a462f2. Configure here.
There was a problem hiding this comment.
dependabot takes digests into account as well, see dependabot/dependabot-core#6628 .
1a462f2 to
1489449
Compare


Continuation of #4462 (comment) asked by @aldy505 .
Quick note: clickhouse version is specified in
build.args.BASE_IMAGEof docker-compose.yml, so it's not getting updated by dependabot.Legal Boilerplate
Look, I get it. The entity doing business as "Sentry" was incorporated in the State of Delaware in 2015 as Functional Software, Inc. and is gonna need some rights from me in order to utilize my contributions in this here PR. So here's the deal: I retain all rights, title and interest in and to my contributions, and by keeping this boilerplate intact I confirm that Sentry can use, modify, copy, and redistribute my contributions, under Sentry's choice of terms.