Skip to content

Auto dependency bump like dependabot #691

@DamianSawicki

Description

@DamianSawicki

Since last week, we've merged 4 PRs bumping various dependencies, and yet new vulnerabilities keep popping up. And in the last 3 months, we've merged 8 PRs bumping dependencies. Theoretically, we probably could have squashed the number of these PRs, but in OSS everyone is free to contribute to the part they find relevant. It would be great to have some automation taking care of bumping dependencies.

Such automation was recently configured in gwctl kubernetes-sigs/gwctl#6, so perhaps we can do the same.

CC: @Michcioperz @dereknola @FelipeYepez

Sub-issues

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions