I see value in it.
But from a legal point of view....there is no human who sends the PR, so in
theory we cannot accept such patches, can we?

Enrico

Il sab 19 ott 2019, 20:26 Tibor Digana <tibordig...@apache.org> ha scritto:

> The dependabot looks interesting, cli has more possibilities than a pure
> button on GUI.
> >> does anyone enabled it
> I am all the ear how it can be enabled.
>
> On Fri, Oct 18, 2019 at 3:32 PM Enrico Olivelli <eolive...@gmail.com>
> wrote:
>
> > Hey guys,
> > Did you see dependabot on our repos?
> >
> > Like this automatic PR
> >
> >
> https://github.com/apache/maven-plugins/pull/147#pullrequestreview-303889692
> >
> > I feel this is very useful, but... does anyone enabled it?
> >
> > Do we have to set a policy, this suggestions are security related fixes,
> we
> > could give them some kind of high priority?
> >
> > Enrico
> >
>

Reply via email to