-
Notifications
You must be signed in to change notification settings - Fork 4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Configure Dependabot security updates? #5341
Comments
Thats too little information. Please provide some more details. |
@jbartosik I updated the description and added example of open source projects that have decided to enable it. |
Thanks. @mwielgus @gjtempleton what do you think? |
Hey @marianafranco, Thanks for the suggestion. There's some potential complexities with our repo setup (particularly in the CA), given we've now started to vendor cloud-provider specific dependencies in not through go.mod files or similar (e.g. the AWS-sdk-go), so I worry we might end up giving ourselves a false sense of security in some regards, though maybe Dependabot can be configured to deal with that? I certainly see no harm in enabling it for the VPA as an initial evaluation given it doesn't have some of the same issues as the CA if you have no objection to it @jbartosik? |
Why Dependabot over Renovate? |
Dependabot can notify of insecure or old library versions, helping to keep dependencies up-to-date.
I have a private fork of 1.21.3 in which dependabot is complaining of some old dependencies.
Why?
Pros:
Cons:
Examples from other open source projects:
The text was updated successfully, but these errors were encountered: