Reconfigure renovate or add dependabot to make sure we get dependency PRs for known security vulnerabilities #1621
Labels
priority: p3
Desirable enhancement or fix. May not be included in next release.
type: feature request
‘Nice-to-have’ improvement, new feature or different behavior or design.
Thanks for stopping by to let us know something could be better!
Is your feature request related to a problem? Please describe.
When this package has a vulnerable dependency, contributors need to manually open a PR and an issue to upgrade said dependencies.
Describe the solution you'd like
Setting up an automated system such as DependaBot would signifiicantly increase the QoL for contributors and users. It would also save time and increase security.
Describe alternatives you've considered
Additional context
You can find a quickstart guide for DependaBot on Github Docs.
The text was updated successfully, but these errors were encountered: