-
Notifications
You must be signed in to change notification settings - Fork 30
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Enhancement: Use dependabot #111
Conversation
87acab2
to
f7a7d54
Compare
f7a7d54
to
2004768
Compare
2004768
to
b411eed
Compare
What's the benefit that we see here ? |
Dependabot can be configured to
For reference, see https://dependabot.com/docs/config-file/. I believe the most compelling argument is that pull requests can be automatically merged. Apart from that, Dependabot has been acquired by GitHub and is the de-facto standard solution for updating dependencies for a wide range of package managers. |
Violinist currently updates |
I feel this would bind us even more to Github and its eco system. Is that a shared concern? If not then we could go ahead. |
ping @localheinz |
b411eed
to
bba96b6
Compare
With Dependabot moving natively into GitHub, I think that the switch makes a lot of sense. In addition, the latest version of Dependabot allows updating GitHub Actions as well. |
This PR
💁♂ This probably requires to set up Dependabot and disable Violinist - is this something you would be up for, @Jan0707?