Update dependencies
Slack
Every Sunday a schedules pipeline "send outdated dependency report to slack" is started and the result can be read in the channel #fs-outdated.
Renovate
Renovate opens merge requests for outdated Composer and Yarn packages (root, deployer/, client/, websocket/, docs/ and tests/e2e/). It runs as the job renovate from the pipeline schedule "Renovate" (SCHEDULED_JOB=renovate), the configuration is in .gitlab/renovate.json.
- Minor and patch updates are grouped per directory. A release has to be 7 days old before it is picked up.
- Dependency Dashboard: Renovate keeps an issue called "Dependency Dashboard" with all pending updates. Major updates and the Playwright packages are not opened automatically. Tick the checkbox of an update, and Renovate opens the MR on its next run (or start the schedule manually under Build → Pipeline schedules).
- At most 2 Renovate MRs are open at the same time. Merge or close one to let the next follow.
- The MRs carry no changelog, look at the package page for release notes.
Update from backend using Composer
Manually check the version
./scripts/composer outdated -D Restricts the list of packages to your direct dependencies
The color coding is as such:
green (=): Dependency is in the latest version and is up to date.
yellow (~): Dependency has a new version available that includes backwards compatibility breaks according to semver, so upgrade when you can but it may involve work.
red (!): Dependency has a new version that is semver-compatible and you should upgrade it.
https://getcomposer.org/doc/03-cli.md#outdated
Structure and explanation of version numbers
- 0.x.x is a beta version. Here every change can contain ``Breaking Changes''.
2.3.5
│ │ │
│ │ └───────── Patch (contains mostly bug fixes)
│ └─────────── Minor version (mostly functional extension)
└───────────── Major version (mostly significant change)
Rules
- Don't mix dev dependencies with dependencies in a commit
- ~ instead of ^ to have similar systems between server and dev computer and to avoid big unwanted changes during yarn update
- only run yarn update if there are only outdated packages with explicit version information
- If you don't know what belongs together, then update only one package per commit.
- Major updates are best done in your own MR.
Update
- Change of version number in composer.json
./scripts/composer update PACKAGENAME* --with-dependencies