You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@tvm.apache.org by GitBox <gi...@apache.org> on 2022/04/20 00:40:19 UTC

[GitHub] [tvm] driazati opened a new pull request, #11072: [ci] Disable dependabot PRs

driazati opened a new pull request, #11072:
URL: https://github.com/apache/tvm/pull/11072

   A bunch of these just got created (e.g. https://github.com/apache/tvm/pull/11070) and are clogging up CI with 2x normal number of builds since they push to a branch and make a PR.
   
   Thanks for contributing to TVM!   Please refer to guideline https://tvm.apache.org/docs/contribute/ for useful information and tips. After the pull request is submitted, please request code reviews from [Reviewers](https://github.com/apache/incubator-tvm/blob/master/CONTRIBUTORS.md#reviewers) by @ them in the pull request thread.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@tvm.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [tvm] driazati commented on pull request #11072: [ci] Disable dependabot PRs

Posted by GitBox <gi...@apache.org>.
driazati commented on PR #11072:
URL: https://github.com/apache/tvm/pull/11072#issuecomment-1105483607

   Dependabot in principle is good but the PR workflow it uses isn’t great for us (it swarms CI with a bunch of jobs since each update spawns 2 CI jobs, one for the PR and another for the in-repo branch). I think it’d be better to use the alerts and do the updates ourselves: https://docs.github.com/en/code-security/dependabot/dependabot-alerts/about-dependabot-alerts


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@tvm.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [tvm] kparzysz-quic commented on pull request #11072: [ci] Disable dependabot PRs

Posted by GitBox <gi...@apache.org>.
kparzysz-quic commented on PR #11072:
URL: https://github.com/apache/tvm/pull/11072#issuecomment-1105443638

   These are security updates.  I think we should at least consider keeping this bot.  There are many new PRs opened because we've fallen behind on security-related updates.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@tvm.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [tvm] kparzysz-quic commented on pull request #11072: [ci] Disable dependabot PRs

Posted by GitBox <gi...@apache.org>.
kparzysz-quic commented on PR #11072:
URL: https://github.com/apache/tvm/pull/11072#issuecomment-1124123384

   Sure, I'm ok with disabling it.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@tvm.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [tvm] areusch merged pull request #11072: [ci] Disable dependabot PRs

Posted by GitBox <gi...@apache.org>.
areusch merged PR #11072:
URL: https://github.com/apache/tvm/pull/11072


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@tvm.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [tvm] areusch commented on pull request #11072: [ci] Disable dependabot PRs

Posted by GitBox <gi...@apache.org>.
areusch commented on PR #11072:
URL: https://github.com/apache/tvm/pull/11072#issuecomment-1124085706

   @kparzysz-quic i do think it would be good to avoid excessive CI load from dependabot. Also, I'm not sure it will know how to work with gen_reqiurements...we'll likely need to adopt a reqiurements.txt style for specifying our deps. maybe we could revisit the PRs when we do that? 


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@tvm.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [tvm] github-actions[bot] commented on pull request #11072: [ci] Disable dependabot PRs

Posted by GitBox <gi...@apache.org>.
github-actions[bot] commented on PR #11072:
URL: https://github.com/apache/tvm/pull/11072#issuecomment-1118002940

   It has been a while since this PR was updated, @areusch please leave a review or address the outstanding comments. @driazati if this PR is still a work in progress, please [convert it to a draft](https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/changing-the-stage-of-a-pull-request#converting-a-pull-request-to-a-draft) until it is ready for review.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@tvm.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org