Skip to content

Conversation

jawnsy
Copy link
Contributor

@jawnsy jawnsy commented Mar 6, 2021

Use dependabot to manage the dependencies defined in go.mod and
GitHub Actions workflows, so that we can proactively update versions.

Outdated versions of third-party dependencies frequently have known
security vulnerabilities with CVEs.

@jawnsy jawnsy self-assigned this Mar 6, 2021
@shortcut-integration
Copy link

This pull request has been linked to Clubhouse Story #8931: Enable additional dependency tracking with dependabot.

@jawnsy jawnsy marked this pull request as ready for review March 6, 2021 23:24
@jawnsy jawnsy requested a review from cmoog March 6, 2021 23:24
Use dependabot to manage the dependencies defined in go.mod and
GitHub Actions workflows, so that we can proactively update versions.

Outdated versions of third-party dependencies frequently have known
security vulnerabilities with CVEs.
@jawnsy jawnsy force-pushed the jawnsy/ch8931/slog-dependabot branch from ff3a808 to b00eb49 Compare May 2, 2021 17:26
@jawnsy jawnsy requested a review from coadler May 2, 2021 17:27
@jawnsy jawnsy merged commit 2e26e52 into master May 3, 2021
@jawnsy jawnsy deleted the jawnsy/ch8931/slog-dependabot branch May 3, 2021 17:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants