You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I've recently been trying to get projects to hash-pin their dependencies and keep them up-to-date with dependabot or renovatebot. I've had mixed results, with many projects questioning the value of such a change.
See here a few of the discussions I've had on this topic. They are all solid discussions with valuable maintainer feedback. I recommend reading them in order since they refer to each other.
I've recently been trying to get projects to hash-pin their dependencies and keep them up-to-date with dependabot or renovatebot. I've had mixed results, with many projects questioning the value of such a change.
See here a few of the discussions I've had on this topic. They are all solid discussions with valuable maintainer feedback. I recommend reading them in order since they refer to each other.
The text was updated successfully, but these errors were encountered: