PR's raised by dependabot #46
Answered
by
nmeans
sushmita-m
asked this question in
Satellite India 2021 Q&A
|
We have started to vendor our packages using my-precious, is there a plan to work on making dependabot PR's cater to these vendored packages? |
Answered by
nmeans
Mar 26, 2021
Replies: 2 comments
|
👋🏽 Browsing security vulnerabilities in the GitHub Advisory Database would help review all the dependencies. We add vulnerabilities to the GitHub Advisory Database from the following sources:
🙇🏽 |
0 replies
|
👋 Hi @sushmita-m! Dependabot supports vendored dependencies for the Bundler (Ruby) and Gomod ecosystems, but not currently for npm via my-precious. We don't have plans to add support for that right now, but I'll be sure and pass along the request to the Dependabot team. |
0 replies
Answer selected by
nmeans
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
👋 Hi @sushmita-m! Dependabot supports vendored dependencies for the Bundler (Ruby) and Gomod ecosystems, but not currently for npm via my-precious. We don't have plans to add support for that right now, but I'll be sure and pass along the request to the Dependabot team.