Manage Ruby dependencies with Dependabot
To help with this, we use a service called Dependabot to perform automated dependency upgrades.
Add Dependabot to a repo
- Give Dependabot access to the repo (only GitHub org owners can do this)
- Go to Dependabot admin and click “Add project”
Ask Dependabot to bump dependencies
By default Dependabot will bump dependencies once a day, but you can ask it to bump manually:
Go to Dependabot admin and click “Bump now” for your project
There are 2 safeguards to prevent unauthorised code changes. Firstly, Dependabot can only update the repositories that we explicitly allow on GitHub. This prevents code changes to other repos. Secondly, we’ve set up branch protection for all repos with the
govuk label. This prevents Dependabot from writing directly to master.