Skip to content

Too frequent unsubstantial patch releases #211

Closed
@infinisil

Description

@infinisil

The new v1.11.x series of patch releases seems to be almost fully automated:

This has lead to 6 patch releases within 2.5 months, without any substantial changes.

The problem with that is that dependabot then also creates automated PRs in all repos that depend on create-github-app-token. As a reviewed of such PRs, I feel like this is a waste of human attention. Especially because patch releases could also contain fixes for security vulnerabilities, so I can't just ignore such PRs.

Suggestion

Automated releases should only happen if there's any substantial updates included, which dependency updates are not.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions