Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enable dependabot package and security updates #1656

Open
mefellows opened this issue Jan 23, 2023 · 2 comments
Open

Enable dependabot package and security updates #1656

mefellows opened this issue Jan 23, 2023 · 2 comments

Comments

@mefellows
Copy link
Member

The current dependabot configuration doesn't automatically raise PRs for Java packages, including security vulnerabilities.

See https://github.com/pact-foundation/pact-jvm/edit/master/.github/dependabot.yml

There has been no security advisories or PRs raised before either, which warrants a review.

@github-actions
Copy link

👋 Thanks, Jira [PACT-649] ticket created.

@github-actions
Copy link

👋 Thanks, this ticket has been added to the PactFlow team's backlog as PACT-650

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant