I see value in it. But from a legal point of view....there is no human who sends the PR, so in theory we cannot accept such patches, can we?
Enrico Il sab 19 ott 2019, 20:26 Tibor Digana <tibordig...@apache.org> ha scritto: > The dependabot looks interesting, cli has more possibilities than a pure > button on GUI. > >> does anyone enabled it > I am all the ear how it can be enabled. > > On Fri, Oct 18, 2019 at 3:32 PM Enrico Olivelli <eolive...@gmail.com> > wrote: > > > Hey guys, > > Did you see dependabot on our repos? > > > > Like this automatic PR > > > > > https://github.com/apache/maven-plugins/pull/147#pullrequestreview-303889692 > > > > I feel this is very useful, but... does anyone enabled it? > > > > Do we have to set a policy, this suggestions are security related fixes, > we > > could give them some kind of high priority? > > > > Enrico > > >