Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Feedback] Unclear value proposition for hash-pinning dependencies and keeping them up-to-date with dependency update tools #3549

Open
pnacht opened this issue Oct 9, 2023 · 2 comments

Comments

@pnacht
Copy link
Contributor

pnacht commented Oct 9, 2023

I've recently been trying to get projects to hash-pin their dependencies and keep them up-to-date with dependabot or renovatebot. I've had mixed results, with many projects questioning the value of such a change.

See here a few of the discussions I've had on this topic. They are all solid discussions with valuable maintainer feedback. I recommend reading them in order since they refer to each other.

Copy link

github-actions bot commented Dec 9, 2023

This issue is stale because it has been open for 60 days with no activity.

Copy link

github-actions bot commented Mar 6, 2024

This issue has been marked stale because it has been open for 60 days with no activity.

@github-actions github-actions bot added the Stale label Mar 6, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: No status
Development

No branches or pull requests

3 participants