weixin_39819393 2020-11-29 10:38 采纳率: 0%
浏览 0

Create PRs for sub-dependencies when there is a security vulnerability

From on November 20, 2017 22:42

github recently alerted us to a downstream dep (in the gemfile.lock brought in from some other dep higher up) security issue, and suggested we make a change to the gemfile to force a newer version of the downstream dep. your bot didn't suggest such a change, but it would be sweet if it did.

happy to provide more context

selection_191

Copied from original issue: dependabot/feedback#53

该提问来源于开源项目:dependabot/dependabot-core

  • 写回答

7条回答 默认 最新

  • weixin_39819393 2020-11-29 10:38
    关注

    Love that new feature from GitHub!

    I'll have a think about what we could do here - I totally agree it would be good for Dependabot to create PRs for security issue in sub-dependencies.

    评论

报告相同问题?