commons-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Bernd Eckenfels <>
Subject Re: Dependabot pr's
Date Thu, 15 Oct 2020 17:57:28 GMT
Before we do that, I need help. I am considering to ignore or unsubscribe the commit mailing
list. Which is IMHO not a good thing (from the point of security reviews). However I cannot
keep up with dependable suggestions (and don’t have an easy way to filter - and frankly
I don’t want to spent any time on finding one)

So can we turn the notifications off or at least send them to a different mailinglist?

Von: John Patrick <>
Gesendet: Wednesday, October 14, 2020 3:17:22 PM
An: Commons Developers List <>
Betreff: Dependabot pr's

to shortcut multiple people telling me not to manually raise pr's to
upgrade dependencies, and dependabot is the preferred option for
commons to be raising these upgrades, and i should raise a pr to
enable dependabot.

so... here are all the pr's to enable dependabot on the repo's which
lack a dependabot.yml file.

They all have the change md5sum for .github/dependabot.yml which
matches the files in the other repos. I don't believe any other change
is required but i might be wrong.


To unsubscribe, e-mail:
For additional commands, e-mail:

  • Unnamed multipart/alternative (inline, None, 0 bytes)
View raw message