-
Notifications
You must be signed in to change notification settings - Fork 1.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Support for Docker compose files #390
Comments
👍 for this, and should be relatively straightforward. A couple of things I want to get to first, but I'm definitely game for adding this to Dependabot at some point! |
Hi, Thanks in advance |
I hope so, yes! This is another one that @hmarr owns on our side, but he's very busy scaling Dependabot up to 100m repos! |
It currently can't SHA-pin the docker-compose.yml `image` keys, so can't help us achieve reproducible builds (dependabot/dependabot-core#390)
@stalebot please leave this open - hoping it gets implemented |
Thanks, @banesullivan. This can work as a temporary solution. |
@mountainash Thank you, but we currently use Dependabot. Switching to another tool would involve a time investment. |
@greysteil is any plan for support this? or use another tool? |
Not sure - I haven't worked on Dependabot for a few years now. @jeffwidman might know? |
Unfortunately I'm also no longer on the Dependabot maintainer team so have no additional insight into this. |
The only solution for me was just using Renovate for everything, either self hosted or as the free GitHub App. |
So I'm guessing we're all jumping ship and boarding Renovate? :P |
Is this still planned? |
Would definitely love this!
|
docker-compose.yaml _One of these days_ 😬 #dependabot/dependabot-core/issues/390
docker-compose.yaml _One of these days_ 😬 #dependabot/dependabot-core/issues/390
Hello everyone, I apologize for the lack of engagement and have some good news to share. Working on Thanks for all the help and support! |
Another update, we expect work to start on this in February. @robaiken will be the developer driving this 😄 |
From @armin-joellenbeck on December 23, 2017 9:21
Knowing when new Docker images are published would be helpful when the are used in a Docker compose file too.
Just like #20, with the file
docker-compose.yml
instead ofDockerfile
.Copied from original issue: dependabot/feedback#66
The text was updated successfully, but these errors were encountered: