Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

enable Dependabot v2 #811

Closed
wants to merge 1 commit into from
Closed

Conversation

sullis
Copy link

@sullis sullis commented Jul 12, 2020

@shashachu
Copy link
Contributor

Hi @sullis, sorry I'm not familiar with Dependabot. Could you add a little more information about what it does and what you're trying to accomplish?

@Tapchicoma
Copy link
Collaborator

@shashachu it is a Github service that automatically updates project dependencies versions. Though support of Gradle is quite limited, see dependabot/dependabot-core#1164

Generally I am not sure if it is good for this project:

  • unnecessary noise by creating PRs for each dependency update, that could lead to several updates for the same dependency until next release
  • doesn't work with Gradle dependency verification - dependabot just bumps versions

@romtsn romtsn closed this Dec 4, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants