Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependabot.yml #4461

Merged
merged 1 commit into from
Jun 20, 2024
Merged

Update dependabot.yml #4461

merged 1 commit into from
Jun 20, 2024

Conversation

dorner
Copy link
Collaborator

@dorner dorner commented Jun 19, 2024

Daily updates are really annoying. Much prefer monthly so I can knock them out at once.

@dorner dorner requested a review from cielf June 19, 2024 21:42
@cielf
Copy link
Collaborator

cielf commented Jun 19, 2024

@dorner I grok that -- only thing I would want to ask is whether there is any security downside, and how we might mitigate it if there is?

@dorner
Copy link
Collaborator Author

dorner commented Jun 20, 2024

It's incredibly rare for a security problem to be so bad that you have to update in less than a month. We don't upgrade Ruby versions for well over a year, and it's far more likely for security to be addressed in big packages like Ruby or Rails, which generally aren't covered by Dependabot because they need manual work.

Copy link
Collaborator

@cielf cielf left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Alright then.

@cielf cielf merged commit 01649c8 into main Jun 20, 2024
38 checks passed
@cielf cielf deleted the dependabot-monthly branch June 20, 2024 16:46
Copy link
Contributor

@dorner: Your PR Update dependabot.yml is part of today's Human Essentials production release: 2024.06.23.
Thank you very much for your contribution!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants