Skip to content

[MINOR] §6: Dependabot does not cover pixi.toml Python toolchain #119

@mvillmow

Description

@mvillmow

Finding

Severity: MINOR
Section: 6
Evidence: .github/dependabot.yml
Principle: YAGNI

Dependabot is configured only for Docker images in /exporter. The Python toolchain dependencies in pixi.toml (bandit, ruff, pytest, yamllint, python) have no automated update mechanism. This means security patches to these tools require manual updates.


Part of #100

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions