Sounds like dependabot is very useful for uncovering insufficient test coverage or missing integration tests :)
Sounds like dependabot is very useful for uncovering insufficient test coverage or missing integration tests :)
On the other hand, very recently, we had to abort a release, because of an outdated dependency that Dependabot DID actually raise.
Which is why I don't want to throw the baby out with the bathwater, as one or two people have suggested.
But I can say that I think that the reality of working with Dependabot, is not very well reflected in popular online articles.
This... is not obvious. It broke a part of your software which you care about. You care, it caused a problem, so it should be tested.
With regards to writing tests of the Django admin, you need to do it if your site is customizing and/or depending upon it.
These kinds of failures are super annoying, but it’s the sort of thing that e2e and canary releases should help you get some coverage on.
Despite the marketing, unit tests are pretty fragile, especially in code with lots of deps (another good reason to limit deps)
So between choosing to write everything themselves (and getting nothing done), writing tests against dependencies (and getting little done due to the overhead), or claiming that external dependencies should have tests of their own, many will pick the latter.
Then again, in a world where create-react-app results in 180 MB of dependencies and about 1500 modules (probably different numbers now, using some older ones from my blog post), auditing security is an uphill battle, not even talking about actual testing.
The situation in the back end development, isn't that much better either, to be honest, because once you look into the complexity of any framework like Spring, Laravel, Django, Rails etc., it becomes apparent that creating a fully featured framework like that is a huge undertaking.
That said, you should at least test the bits where the external dependency is integrated with your codebase.
That's unfortunate! For the project I'm working on, we've "solved" that by showing the number of test and the difference to the number of tests that ran on main.
FWIW, at previous jobs, upgrading Java dependencies was a major pain because they were all outdated and the latest versions introduced too many breaking changes for us. At my current job, we pretty much instantly merge all PRs from dependabot because we trust our CI. Upgrades rarely introduce problems and if they do, they are easy to fix.
There's your problem.