Skip to content
This repository has been archived by the owner on Apr 2, 2024. It is now read-only.

Bump python dependencies, raise PRs monthly #30

Merged
merged 1 commit into from
Oct 19, 2023
Merged

Conversation

NovemberTang
Copy link
Contributor

What does this change?

  1. Dependabot will update python dependencies
  2. Version bumps will happen once a month

Why?

  1. The app is written in python, this is probably the most important code to have covered.
  2. Constant dependency update PRs create a lot of noise, and mean we spend more time on version bumps, and less time on securing the department. Let's free up some time. If there are serious vulnerabilities that show up between dependabot PRs, we can patch them manually, or dependabot will raise a PR in the interim.

@NovemberTang NovemberTang merged commit bbee56e into main Oct 19, 2023
3 checks passed
@NovemberTang NovemberTang deleted the nt/dependabot branch October 19, 2023 12:06
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants