Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enable dependabot #50

Merged
merged 2 commits into from
Apr 26, 2021
Merged

Enable dependabot #50

merged 2 commits into from
Apr 26, 2021

Conversation

jaraco
Copy link
Owner

@jaraco jaraco commented Apr 26, 2021

Supersedes #42

@jaraco jaraco merged commit 2f690f6 into main Apr 26, 2021
@jaraco jaraco deleted the dependabot branch April 26, 2021 01:19
@jaraco
Copy link
Owner Author

jaraco commented May 13, 2021

Dependabot isn't very smart. Consider pmxbot/pmxbot#91, where dependabot unpins a dependency that's protected by a comment. If accepted, that pull request would leave a comment that's potentially no longer relevant to the version. If wonder if there's some syntax that could be used in the comment that would signal to dependabot why the dependency is pinned and what factors would need to change to revisit the pin (i.e. the referenced bug is fixed, a new release is made, and the minimum version now includes that new release).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants