Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Configure Dependabot security updates? #5341

Closed
marianafranco opened this issue Nov 30, 2022 · 5 comments · Fixed by #5567
Closed

Configure Dependabot security updates? #5341

marianafranco opened this issue Nov 30, 2022 · 5 comments · Fixed by #5567
Labels
kind/feature Categorizes issue or PR as related to a new feature.

Comments

@marianafranco
Copy link

marianafranco commented Nov 30, 2022

Dependabot can notify of insecure or old library versions, helping to keep dependencies up-to-date.

I have a private fork of 1.21.3 in which dependabot is complaining of some old dependencies.

Why?

Pros:

Cons:

  • More noise from the bot (depends on how you configure it).

Examples from other open source projects:

@marianafranco marianafranco added the kind/feature Categorizes issue or PR as related to a new feature. label Nov 30, 2022
@jbartosik
Copy link
Collaborator

Thats too little information. Please provide some more details.

@marianafranco
Copy link
Author

@jbartosik I updated the description and added example of open source projects that have decided to enable it.

@jbartosik
Copy link
Collaborator

Thanks.

@mwielgus @gjtempleton what do you think?

@gjtempleton
Copy link
Member

Hey @marianafranco,

Thanks for the suggestion.

There's some potential complexities with our repo setup (particularly in the CA), given we've now started to vendor cloud-provider specific dependencies in not through go.mod files or similar (e.g. the AWS-sdk-go), so I worry we might end up giving ourselves a false sense of security in some regards, though maybe Dependabot can be configured to deal with that?

I certainly see no harm in enabling it for the VPA as an initial evaluation given it doesn't have some of the same issues as the CA if you have no objection to it @jbartosik?

@sanmai-NL
Copy link

Why Dependabot over Renovate?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/feature Categorizes issue or PR as related to a new feature.
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants