action-update VS globus-group-manager

Compare action-update vs globus-group-manager and see what are their differences.

action-update

Build GitHub Actions that update dependencies. (by thepwagner)

globus-group-manager

Stanford Globus Group Manager: Integrate Stanford Workgroups and Globus Groups (by stanford-rc)
InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
action-update globus-group-manager
1 2
1 0
- -
2.8 0.0
almost 3 years ago 29 days ago
Go Python
MIT License GNU Affero General Public License v3.0
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.

action-update

Posts with mentions or reviews of action-update. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2022-05-25.
  • We use Dependabot to secure GitHub
    10 projects | news.ycombinator.com | 25 May 2022
    > That would be nice. It could even run on top of the GH Actions infrastructure now.

    https://github.com/thepwagner/action-update being an example of this (and showing go, docker)

    > it seems like part of the overhead in maintaining dependabot is that there is ruby code reimplementing yarn logic

    The entire maintenance burden of dependabot is "reimplement logic that package managers already do to determine the update strategy." Using package managers functionality for this would indeed make this a lot easier, though even then package manager support for specific things might not be universal.

    That said, it's possibly easier to go to the package manager and say "we'd like to implement/for you to implement feature X that will enable Dependabot as well as the underlying functionality Dependabot was missing, that your users probably already want" than the opposite problem of people asking Dependabot to write a bunch of ruby to re-implement something that already exists.

globus-group-manager

Posts with mentions or reviews of globus-group-manager. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2022-07-19.
  • Use `Python -m Pip`
    10 projects | news.ycombinator.com | 19 Jul 2022
    It has only recently sunk in for me that, with the latest versions, Pip is not a tool for maintaining an environment and list of dependencies (where you'd have a lockfile, for example). Instead, it is an interface to…

    1. Download packages from PyPi (or a different repository that provides the same interface)

    2. Read the pyproject.toml file to find the build backend to use, and then install that.

    3. Call the build backend to actually do the installation. This can be Poetry, Setuptools, Flit, or something else.

    Pipenv is another such interface.

    PEP 517 (https://peps.python.org/pep-0517/) created pyproject.toml and defined the API that build backends follow. That API includes a way for the build backend to tell Pip (or Pipenv, etc.) what dependencies to install. For systems that have a lockfile (like Pipenv), that could be a list of packages with explicit versions.

    PIP 660 extended PEP 517, defining a standard way to have "editable installs". In other words, a way to support `pip install -e package`, or even `pip install -e .`.

    The above is all my understanding, which is not at all authoritative!

    It's worth checking out the list of packaging-related PEPs: https://peps.python.org/topic/packaging/ It's worth reading PEPs 518 and 621.

    As an example, here's a Python package that uses Poetry: https://github.com/globus/globus-timer-cli It works perfectly fine with Pip, because Pip sees (via `pyproject.toml`) that it needs to pull in Poetry, and call it to do the actual install.

    Here's an older repo of mine, where I've just started to learn about the transition: https://github.com/stanford-rc/mais-apis-python/blob/main/py... In this case, I could delete `pyproject.toml` entirely, Pip would see the `setup.py` file, and understand to use Setuptools. This was me when I was just starting to learn about the transition.

    Finally, here's a newer repo of mine, where I've ditched setup.py (and _almost_ ditched setup.cfg) entirely: https://github.com/stanford-rc/globus-group-manager I'm still using Setuptools, but all of the metadata and requirements are included in the `pyproject.toml` file.

    It's definitely been a rocky transition, but it's really looking (to me, at least) like we're at (or near) the point where I can just use `pip install …` and it'll work, regardless of the build backend in use!

  • We use Dependabot to secure GitHub
    10 projects | news.ycombinator.com | 25 May 2022
    I very much appreciate Dependabot! I like how it can pick up dependencies in interesting places.

    For example, the Globus @ Stanford web site (https://globus.stanford.edu) uses GitHub Pages (repo at https://github.com/stanford-rc/globus.stanford.edu). I have a Gemfile in the repo: When I want to test changes locally, I use Bundler to install everything I need, and to launch Jekyll. Even though the Gemfile isn't used 'in production', Dependabot still warns me, so that I don't run older, vulnerable software on my laptop.

    At the same time, I can't be sure if Dependabot is picking up dependencies for my Python project.

    In my latest project (https://github.com/stanford-rc/globus-group-manager), I'm using pyproject.toml to hold all of the Python dependencies for the project, something that Setuptools is now supporting experimentally (woot!). I've configured Dependabot, and it has picked up my repo's `pyproject.toml` file, but I can't tell if it has actually cataloged my Python dependencies.

    Looking around the web also does not give me a clear answer. For example, https://github.com/dependabot/feedback/issues/57 is titled "pyproject.toml support", but it refers specifically to Poetry (and indeed, Poetry v1 is listed as supported at https://docs.github.com/en/code-security/dependabot/dependab...). But Setuptools is not.

    https://github.community/t//2576 asks about Setuptools support, and has been pretty dormant. I thought setup.cfg was supported after https://github.com/dependabot/dependabot-core/pull/3423, but another project of mine (https://github.com/stanford-rc/mais-apis-python/network/depe...) doesn't show anything for setup.cfg.

What are some alternatives?

When comparing action-update and globus-group-manager you can also consider the following projects:

mais-apis-python - Python client for Stanford MaIS APIs

dependabot-core - 🤖 Dependabot's core logic for creating update PR's.