Conversation
87acab2 to
f7a7d54
Compare
f7a7d54 to
2004768
Compare
2004768 to
b411eed
Compare
|
What's the benefit that we see here ? |
|
Dependabot can be configured to
For reference, see https://dependabot.com/docs/config-file/. I believe the most compelling argument is that pull requests can be automatically merged. Apart from that, Dependabot has been acquired by GitHub and is the de-facto standard solution for updating dependencies for a wide range of package managers. |
|
Violinist currently updates |
|
I feel this would bind us even more to Github and its eco system. Is that a shared concern? If not then we could go ahead. |
|
ping @localheinz |
b411eed to
bba96b6
Compare
|
With Dependabot moving natively into GitHub, I think that the switch makes a lot of sense. In addition, the latest version of Dependabot allows updating GitHub Actions as well. |
This PR
💁♂ This probably requires to set up Dependabot and disable Violinist - is this something you would be up for, @Jan0707?