Dave Cross · @davorg
45 followers · 161 posts · Server fosstodon.org

The contents of this blog post have proven very useful today. The actions/checkout version was updated recently, and I've received a large number of PRs from Dependabot that just needed to be accepted.

dev.to/davorg/dependabot-and-g

#github #githubactions #dependabot

Last updated 2 years ago

Laura Vuorenoja · @lauravuo
6 followers · 12 posts · Server fosstodon.org

Just noticed that can update versions. A needed feature indeed, so far I have been manually monitoring the repository tags for updates

github.blog/changelog/2023-03-

#dependabot #githubactions

Last updated 2 years ago

markus staab · @markusstaab
109 followers · 273 posts · Server phpc.social

Anyone interessted in supporting vendoring for dependencies?

it means dependabot would commit the vendor/ dir and not just updates composer.lock/json. its really usefull for e.g. app repositories.

if so, please vote

github.com/dependabot/dependab

#dependabot #php

Last updated 2 years ago

Vincent Biret · @vincentbiret
50 followers · 291 posts · Server hachyderm.io
GitHub · @github
86 followers · 140 posts · Server techhub.social
John McLear · @johnmclear
118 followers · 537 posts · Server mastodon.green

Any users know how to give dependabot access to secret keys so sauce labs tests will run?

#saucelabs #GitHub #dependabot #foss

Last updated 2 years ago

musicmatze :rust: :nixos: · @musicmatze
887 followers · 2925 posts · Server social.linux.pizza

1st of the month is day in many repos.

That means hundreds of notification mails from github and merging orgy.

#github #dependabot

Last updated 2 years ago

Ozzy · @Ozzy
90 followers · 453 posts · Server social.linux.pizza

@khmarbaise and use and @snyk they will keep you upto date enough

#dependabot

Last updated 2 years ago

Ross A. Baker · @ross
797 followers · 822 posts · Server social.rossabaker.com

sbt-dependency-submission is a nifty GitHub Action to report dependencies at build time for vulnerability scanning. It even sees your transitive dependencies. But it can be hard to debug why a dependency was submitted.

In ~/.sbt/1.0/sbt-dependency-submission.sbt:

```
addSbtPlugin("ch.epfl.scala" % "sbt-github-dependency-submission" % "2.1.2")`
```

Now you can run `show githubDependencyManifest` to debug!

#scala #dependabot

Last updated 2 years ago

aegilops :github::microsoft: · @aegilops
143 followers · 527 posts · Server fosstodon.org

Yesterday πŸ—“οΈ I made a prototype βš™οΈ to improve :github: when using .

πŸ‘‰ If you’d like to try it out, and promise πŸ™ to give feedback πŸ—£οΈ, I can give a few people access to a private πŸ”’ repo before I open source πŸ€—something - just drop me your GitHub handle please.

Read on πŸ‘€ for how it works πŸ‘‡

#github #dependabot #golang #sca #appsec #supplychainsecurity #dependencysubmission #ast #abstractsyntaxtree #githubadvisorydatabase #vulnerabilitymanagement

Last updated 2 years ago

Francis · @francis
212 followers · 161 posts · Server mastodon.uno

What do you use to track dependency updates?

#node #dependencies #dependabot #renovate

Last updated 2 years ago

GitHub · @github
7 followers · 42 posts · Server techhub.social
Jimmy B. :apple_inc: · @jimmyb
22 followers · 567 posts · Server selfhosted.cafe
Aral Balkan · @aral
34406 followers · 24777 posts · Server mastodon.ar.al

Anyone else getting swarms of email notifications today that Dependabot was enabled on their GitHub repositories?

#github #dependabot

Last updated 2 years ago

Ross A. Baker · @ross
766 followers · 578 posts · Server social.rossabaker.com

Dependabot finds things we don't, but vulnerability fatigue is real. We have a telemetry client that uses OkHttp. We don't write Kotlin, we don't use our telemetry client in a way that invokes Kotlin, and our client probably doesn't use the vulnerable parts of Kotlin. But every Scala repo will be pinged about every Kotlin stdlib vulnerability because it's dormant on the classpath.

#security #dependabot

Last updated 2 years ago

Robert · @xoxys
57 followers · 333 posts · Server social.tchncs.de

@bodsch@mastodon.socia l Hopefully you don't want to tell me that your chosen language Python is hassle-free :mastorofl: The "best" language doesn't help if the developer can't handle it properly.

Anyway, I guess I won't convince you, but I'm very grateful to have a full alternative to and does a solid job here.

#renovatebot #dependabot #opensource

Last updated 2 years ago

Fredrik Averpil :python: · @fredrikaverpil
156 followers · 344 posts · Server fosstodon.org

Here's a neat little tip on how you can use 's new "merge queue" feature to ease the pain with churn:

fredrikaverpil.github.io/blog/

#github #dependabot

Last updated 2 years ago

Juan Luis · @astrojuanlu
1208 followers · 1513 posts · Server social.juanlu.space
Ben Ramsey :elephpant_rainbow: · @ramsey
3026 followers · 5236 posts · Server phpc.social

Does no longer automatically rebase PRs?

#dependabot #github

Last updated 2 years ago

Foojay.io · @foojay
564 followers · 290 posts · Server foojay.social

Did you know bots can automatically create pull requests to keep dependencies secure and up to date? @maritvandijk compares and contrasts , , and on Foojay :foojay: Today!

foojay.io/today/using-bots-to-

#renovate #dependabot #snyk #foojaytip #java #kotlin

Last updated 2 years ago