Skip to content

Conversation

@cclauss
Copy link
Contributor

@cclauss cclauss commented Jul 27, 2024

@cclauss cclauss requested a review from jpakkane as a code owner July 27, 2024 21:41
@eli-schwartz
Copy link
Member

We have previously rejected dependabot. I do not wish to use such hostilely designed software.

@eli-schwartz
Copy link
Member

Fixes software supply chain safety warnings

Although I'm unsure what you mean by this, since the warnings in question have zero relationship to "supply chain safety". They have to do with something else entirely...

@eli-schwartz
Copy link
Member

For a bit of additional context, adding a (badly designed) bot to automatically make PRs would not help us in any way -- we don't really need the reminder to update, per the discussion on the linked ticket I had been working on this exact matter back in March -- the problem is that it does not, in fact, actually work. Updating the actions versions breaks the CI, it's that simple. Even the linked PR doesn't update all of them, and that's a nontrivial part of the discussion in that PR. Dependabot would simply open a useless PR that breaks the CI and would be closed or ignored.

@cclauss cclauss deleted the patch-1 branch July 28, 2024 03:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants