rombert commented on PR #6: URL: https://github.com/apache/sling-org-apache-sling-jcr-davex/pull/6#issuecomment-5241137288
> If they are not managed by the parent pom, should they be _updated_? The Dependabot guidance applies to all dep updates IMO ( https://cwiki.apache.org/confluence/spaces/SLING/pages/210079609/Dependabot ), and this would be a case of "updating the versions of dependencies to be the oldest compatible version that does not have known security vulnerabilities ". If we have a reason to update, we do it. But we don't generally push the latest update for dependencies. Exception are runtime dependencies, e.g. Sling Starter. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
