Skip to content

chore: use dependabot to manage dependencies #2830

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 4 commits into from
Mar 12, 2021
Merged

chore: use dependabot to manage dependencies #2830

merged 4 commits into from
Mar 12, 2021

Conversation

jawnsy
Copy link
Contributor

@jawnsy jawnsy commented Mar 6, 2021

Use dependabot to manage the dependencies defined in package.json and
GitHub Actions workflows, so that we can proactively update versions.

Outdated versions of third-party dependencies frequently have known
security vulnerabilities with CVEs.

Use dependabot to manage the dependencies defined in package.json and
GitHub Actions workflows, so that we can proactively update versions.

Outdated versions of third-party dependencies frequently have known
security vulnerabilities with CVEs.
@jawnsy jawnsy requested a review from a team as a code owner March 6, 2021 21:45
@shortcut-integration
Copy link

This pull request has been linked to Clubhouse Story #8931: Enable additional dependency tracking with dependabot.

@jawnsy jawnsy changed the title chore: use dependabot to manage dependencies #259 chore: use dependabot to manage dependencies Mar 6, 2021
Copy link
Contributor

@jsjoeio jsjoeio left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the contribution, @jawnsy! 🎉

In the past when I've used dependabot to manage dependencies, it tends to be pretty noisy and can be overwhelming to keep up with.

Just took a look at the Security tab of our repo and it looks like we can set a lot of this up through there, including dependabot alerts.

image

Do you know the difference between using that vs adding this in like you've done?

@jsjoeio
Copy link
Contributor

jsjoeio commented Mar 9, 2021

bump @jawnsy

@code-asher
Copy link
Member

I'm down to own these if that's helpful.

jsjoeio
jsjoeio previously approved these changes Mar 11, 2021
Copy link
Contributor

@jsjoeio jsjoeio left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@jawnsy
good luck han solo gif

@jawnsy jawnsy self-assigned this Mar 12, 2021
@jawnsy jawnsy requested a review from a team March 12, 2021 19:30
@jawnsy jawnsy merged commit 7b1fe31 into coder:main Mar 12, 2021
@jawnsy jawnsy deleted the jawnsy/ch8931/dependabot branch March 12, 2021 19:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants