Dependabot

957 posts

Dependabot banner
Dependabot

Dependabot

@dependabot

A friendly @GitHub-native robot that helps you keep your dependencies up to date

Katılım Mayıs 2017
39 Takip Edilen1.9K Takipçiler
Dependabot retweetledi
Charlie Marsh
Charlie Marsh@charliermarsh·
Dependabot support for uv just went GA 🎉🎉🎉
Charlie Marsh tweet media
English
6
23
302
10.9K
Dependabot retweetledi
Mark Allen
Mark Allen@markhenryallen·
Do you use the bun package manager and dependabot? If so, you might want to try the experimental support for bun in dependabot. Add `enable-beta-ecosystems: true` to your `dependabot.yml` and add the `npm` package ecosystem. You can see an example below. Let me know if you try this!
English
3
3
19
3.4K
Rajat 🇮🇳👨‍💻
Rajat 🇮🇳👨‍💻@rsaxena_rajat·
Hi @dependabot ! I would like to receive alerts and PRs for dependency related vulnerabilities on a branch different from the default one in a repo. Is there any configuration that can help? Thanks !
English
1
0
1
32
Dependabot
Dependabot@dependabot·
@bcomnes Dependabot on standard GitHub-hosted runners (the default) does not count towards GitHub Actions minutes – meaning that using Dependabot continues to be free for everyone 😀
English
0
0
2
21
Bret Comnes
Bret Comnes@bcomnes·
Seeing dependabot logs in the actions tab now. Are they charging run time on those now? Or just surfacing logs more consistently.
English
2
0
0
96
Dependabot retweetledi
hyperprior
hyperprior@hyperprior·
@forstmeier don’t hate the player hate the weekly openssh CVE game
English
0
1
2
291
Alexander Moerman
Alexander Moerman@amoerie·
It's such a nice little gesture when @dependabot gives a thumbs up after you give it a command, wonderful design
Alexander Moerman tweet media
English
2
1
6
232
Dependabot
Dependabot@dependabot·
Are you passionate about multidirectory configuration in the dependabot.yml? What do you think should happen when directories overlap? Let us know in the poll! github.com/dependabot/dep…
English
0
0
0
375
Dependabot retweetledi
Justin Hutchings
Justin Hutchings@jhutchings0·
Five years ago today, we were at GitHub Satellite Berlin announcing that GitHub acquired @dependabot . In the time since, Dependabot has helped secure the software supply chain for millions of developers across the world by creating automatic fixes for vulnerable dependencies.
Justin Hutchings tweet media
English
2
8
40
8.4K
Dependabot retweetledi
Jonathan Wilke
Jonathan Wilke@jonathan_wilke·
I just found out you can group @dependabot updates 🤯 No more "25 open pull requests". Just put these lines into your dependabot.yml:
Jonathan Wilke tweet media
English
1
4
34
5.4K
Dependabot retweetledi
Carolyn Galvin
Carolyn Galvin@cmcgalvin·
Really excited to have had the support of the rest of the Dependabot PM team to get this change over the line! It was a long time coming. github.blog/changelog/2024…
English
0
1
2
255
Dependabot retweetledi
GitHub
GitHub@github·
You can now run Dependabot as a GitHub Actions workflow! 🌟 Read more about the benefits this unlocks, including self-hosted runner support. github.blog/2024-05-02-dep…
English
4
33
133
84.9K