Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

🔧 [dependabot] Enable automated updates for indirect dependencies #747

Merged
merged 1 commit into from
Dec 27, 2021

Conversation

cjolowicz
Copy link
Owner

@cjolowicz cjolowicz commented Dec 27, 2021

Configure Dependabot to keep both direct and indirect dependencies updated.

While the default setting of upgrading only direct dependencies means less churn, it also results in checks being run with increasingly outdated dependencies -- unless users are mindful of performing frequent manual updates. But typically they won't be because this project template appears to be automating all dependency updates. Often these outdated dependencies are only discovered when they get flagged by safety or Dependabot alerts due to security vulnerabilities.

@cjolowicz cjolowicz added the ci Continuous Integration label Dec 27, 2021
@cjolowicz cjolowicz merged commit 886150f into main Dec 27, 2021
@cjolowicz cjolowicz deleted the ci/dependabot-subdependencies branch December 27, 2021 17:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ci Continuous Integration
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant