-
-
Notifications
You must be signed in to change notification settings - Fork 18
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
an option to make MRs only for insecure deps #29
Comments
Yes, dependabot can do it: wemake-services/wemake-django-template#749 Here's my idea:
Please, report if that works for you. |
thanks for the tip. |
@lorvent ok, I will do it in ~7 days. |
Still no solution from my side. Sorry. Any ideas? |
are we checking for deps using dependabot api or directly checking with packagist.org and nmpjs.com ? depending on that...we should findout may be. |
Nope, just |
but i can't find any api link for dependabot. can you please provide link? |
I am not quite familiar with dependabot's code base and |
hmm, lets hope someone else will make a PR for it, since they already have option to filter by security update or not. |
Hello,
dependabot says it can check for insecure deps.
is there anyway, we can do same here with kira?
we have a php/laravel application where we use old versions intentionally, it is making MRs for latest versions which could break application.
so i want to know, if there is any way to achieve what i want i.e. let bot create MRs only for security vulnerabilities.
thanks
The text was updated successfully, but these errors were encountered: