Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Q2 Dependabot application dependency updates #172

Closed
nathankota opened this issue Sep 6, 2023 · 3 comments
Closed

Q2 Dependabot application dependency updates #172

nathankota opened this issue Sep 6, 2023 · 3 comments
Assignees

Comments

@nathankota
Copy link
Contributor

nathankota commented Sep 6, 2023

Benefit Hypothesis

UGRC applications have dependencies that are constantly updating to add new features, improve performance, and patch security issues. Keeping applications current with dependencies improves our security posture and allows for easier future enhancements since the amount of breaking changes is smaller and more trivial.

Acceptance Criteria

UGRC application dependencies are current and all known CVE's are patched.

@nathankota nathankota converted this from a draft issue Sep 6, 2023
@nathankota
Copy link
Contributor Author

nathankota commented Sep 6, 2023

Sprint 1 Tasks

  • Investigate and implement some Dependabot groups

  • Dependabot updates

  • Sort out Google Analytics

  • make git checkout quiet with

     with:
        show-progress: false
  • Trusted publishers for PyPi

Bump to next quarter

@steveoh
Copy link
Member

steveoh commented Oct 13, 2023

Sprint 1 Notes

Scott and Steve have completed 99% of this quarters dependabot updates. Below are some tasks that we have to close out the objective and some we want to push to the next quarter.

Remaining tasks

  • API Client build needs to be investigated
  • Parole needs code changes
  • Address point editor needs updates but we aren’t sure where to invest time
  • Jake hasn't started his python projects
  • Revisit the reactfire npm conflicts
  • Some action workflows are not completing since their required checks aren’t running

Next quarter

  • Forklift arcpy + warehouse updates we'd like to push for next quarter
  • Push swapper to pypi and automate builds Pypi swapper#19

@nathankota
Copy link
Contributor Author

will move unchecked tasks and new ones to a Q3 feature

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: Done
Development

No branches or pull requests

4 participants