Skip to content

Conversation

@briri
Copy link
Collaborator

@briri briri commented Sep 5, 2025

Adding a configuration file that instructs Dependabot to work against the v5 branch and to check npm, bundler and Dockerfile for vulnerabilities

@briri briri requested a review from jupiter007 September 5, 2025 12:37
jupiter007
jupiter007 previously approved these changes Sep 5, 2025
Copy link
Collaborator

@jupiter007 jupiter007 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice. Do you think we should be pointing the dependabot scans to run against our development branches so that we catch vulnerabilities before they are on main? That way we can test the updates before they are live.

@briri briri changed the base branch from main to v5 September 8, 2025 17:17
@briri
Copy link
Collaborator Author

briri commented Sep 8, 2025

Nice. Do you think we should be pointing the dependabot scans to run against our development branches so that we catch vulnerabilities before they are on main? That way we can test the updates before they are live.

Yes! I'm thinking that would be a great idea in the new repos

@briri briri changed the base branch from v5 to main September 8, 2025 17:18
@briri briri dismissed jupiter007’s stale review September 8, 2025 17:18

The base branch was changed.

@briri briri merged commit 86f4b84 into main Sep 8, 2025
0 of 9 checks passed
@briri briri deleted the chore/dependabot-config branch September 8, 2025 17:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants