Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Leverage Dependabot for automatic dependencies monitoring #43

Open
Toparvion opened this issue Jun 22, 2020 · 0 comments
Open

Leverage Dependabot for automatic dependencies monitoring #43

Toparvion opened this issue Jun 22, 2020 · 0 comments
Assignees

Comments

@Toparvion
Copy link
Owner

As far as AnaLog receives the developers' attention on from-time-to-time basis, it is important to keep an eye on its dependencies set because there can appear stale or even insecure libraries.
For a GitHub hosted project, the easiest way to achieve this seems to leverage Dependabot.
The issue supposes the application of the bot only. Its further customization can be addressed in successive issues as the need arises.

@Toparvion Toparvion self-assigned this Jun 22, 2020
@Toparvion Toparvion changed the title Leverage DependaBot for automatic dependencies monitoring Leverage Dependabot for automatic dependencies monitoring Jun 22, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant