From on November 20, 2017 22:42
github recently alerted us to a downstream dep (in the gemfile.lock brought in from some other dep higher up) security issue, and suggested we make a change to the gemfile to force a newer version of the downstream dep. your bot didn't suggest such a change, but it would be sweet if it did.
happy to provide more context

Copied from original issue: dependabot/feedback#53
该提问来源于开源项目:dependabot/dependabot-core