Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Don't update your dependencies manually. Setup renovate to do it for you, with a delay of at least a couple of weeks, and enable vulnerability alerts so that it opens PRs for publicly known vulnerabilities without delay

https://docs.renovatebot.com/configuration-options/#minimumr...

https://docs.renovatebot.com/presets-default/#enablevulnerab...



Why was this comment downvoted? Please explain why you disagree.


I didn’t downvote, but...

Depending on a commercial service is out of the question for most open source projects.


Renovate is not commercial, it's an own source dependabot, quite more copable at that.


AGPL is a no-go for many companies (even when it's just a tool that touches your code and not a dependency you link to).


good. that's the point.

agpl is a no go for companies not intending to ever contribute anything back. good riddance.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: