Skip to content

Reconfigure renovate or add dependabot to make sure we get dependency PRs for known security vulnerabilities #208

@SmashingQuasar

Description

@SmashingQuasar

Thanks for stopping by to let us know something could be better!

Is your feature request related to a problem? Please describe.

When this package has a vulnerable dependency, contributors need to manually open a PR and an issue to upgrade said dependencies.

Describe the solution you'd like

Setting up an automated system such as DependaBot would signifiicantly increase the QoL for contributors and users. It would also save time and increase security.

Describe alternatives you've considered

Additional context

You can find a quickstart guide for DependaBot on Github Docs.

Metadata

Metadata

Assignees

Labels

priority: p3Desirable enhancement or fix. May not be included in next release.size: mPull request size is medium.type: feature request‘Nice-to-have’ improvement, new feature or different behavior or design.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions