Skip to content

Conversation

@vmcj
Copy link
Member

@vmcj vmcj commented Nov 25, 2025

We already set updates for non-security to 0 (see: https://docs.github.com/en/code-security/dependabot/working-with-dependabot/dependabot-options-reference#open-pull-requests-limit-) so this change should only open PRs for security issues. IMO this is fine for released versions as we have CI to check for the possible issues.

This would give issues when we need to pin to an unmaintained dependency where an update would require an update to a root dependency. I think in case we don't want to update in that case we can handle it case by case, but we should be aware of such an issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant