Hacker News new | past | comments | ask | show | jobs | submit login

Just another reason not to use dependabot - it's default configuration appears to be created to burn money on GH Actions / Azure.



Just one more reason to actually read the article instead of just assuming its contents say whatever you want.


That's a silly conclusion. This is not dependabot specific - you can achieve the same with any system automatically suggesting merges.


fair point. I think I've just been burned too many times by dependabot looking to update single ts packages with single line changes. it's default configuration is overly aggresive


Dependabot doesn't try to guess what's in the changes. It can't really tell anyway. A trivial 1 line change may be either "this box is now 1px further to the right", or "a critical bug which will delete all your data tomorrow is fixed". It's up to dependabot to report any change available.


Looks like several of the core contributors work for github.

    It is difficult to get a man to understand something, when his salary depends on his not understanding it.


May 23, 2019: "Dependabot has been acquired by GitHub and we couldn't be more excited!" https://web.archive.org/web/20190601064131/https://dependabo...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: