Dependabot poll #351
floydspace
started this conversation in
Polls
Replies: 1 comment
-
I think given we have something of an e2e in place now it should be relatively low risk |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hey @samchungy and the community
What do you think about Dependabot PRs? is it safe just simply merge them? Does anybody faced with the dependencies issues produced by Dependabot.
My personal idea is: if we are locking our dependencies than we are assure that the app works properly with them, but when dependabot reshuffle them I'm getting not comfortable about dependencies. and all the PRs created by the bot is annoying.
But on the other hand, it serves for better: fixing vulnerabilities in out deps, why not to use this privilege.
As long as it's not my personal project anymore, I'd like to get some opinion from community.
Thank you for voting.
1 vote ·
Beta Was this translation helpful? Give feedback.
All reactions