Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Limit dependabot to run-time dependencies only. #3402

Merged
merged 1 commit into from
Mar 2, 2022
Merged

Conversation

vidartf
Copy link
Member

@vidartf vidartf commented Mar 2, 2022

Make dependabot only make PRs for versions that affect runtime dependencies. This would mean that we would not be getting security updates pushed automatically for dev dependencies. However, developers should still be able to receive a notice about security updates by running yarn audit locally (npm does this by default on install command, and yarn may change to that in the future as well).

@github-actions
Copy link

github-actions bot commented Mar 2, 2022

Binder 👈 Launch a binder notebook on branch jupyter-widgets/ipywidgets/dependabot-fix

@jasongrout
Copy link
Member

Thanks!

@jasongrout jasongrout merged commit 949ccde into master Mar 2, 2022
@martinRenou martinRenou deleted the dependabot-fix branch March 2, 2022 17:12
@jasongrout jasongrout added this to the 8.0 milestone Mar 8, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants