Skip to content

Should we keep the github dependabot? #255

@lholmquist

Description

@lholmquist

Githubs dependency bot has been sending PR's, that i believe we have merged in the past. There is one open one right now, #254

But i was thinking, do we really need this since these updates have only been to the package-lock.json and since this is a module, that file never gets published, so the end user will never get any benefit it might have.

We are already using snyk to update the "main" dependencies. So does it make sense to keep this bot and have all these little micro-updates that won't ever really make it to a published version?

Metadata

Metadata

Assignees

No one assigned

    Labels

    type/questionFurther information is requested

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions