Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Disable dependabot for ibc-go #3429

Closed
rootulp opened this issue May 2, 2024 · 1 comment
Closed

Disable dependabot for ibc-go #3429

rootulp opened this issue May 2, 2024 · 1 comment
Labels
needs:discussion item needs to be discussed as a group in the next sync. if marking an item, pls be prepped to talk

Comments

@rootulp
Copy link
Collaborator

rootulp commented May 2, 2024

Context

#3282

Problem

ibc-go minor releases can contain state machine breaking changes per their release policy. IMO that's extremely unexpected behavior because it means we can only bump the ibc-go dependency when executing hard-forks. Dependabot PRs make it extremely easy to merge (and potentially backport) a consensus breaking change.

Proposal

Disable dependabot for ibc-go so we have to opt-in to upgrading ibc-go on main and release branches.

@rootulp rootulp added the needs:discussion item needs to be discussed as a group in the next sync. if marking an item, pls be prepped to talk label May 2, 2024
@rootulp
Copy link
Collaborator Author

rootulp commented May 3, 2024

This is easy to revert so I just went ahead and did it. #3431

@rootulp rootulp closed this as completed May 3, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
needs:discussion item needs to be discussed as a group in the next sync. if marking an item, pls be prepped to talk
Projects
None yet
Development

No branches or pull requests

1 participant