pjfanning opened a new issue, #1554:
URL: https://github.com/apache/incubator-streampark/issues/1554

   ### Search before asking
   
   - [X] I had searched in the 
[feature](https://github.com/apache/streampark/issues?q=is%3Aissue+label%3A%22Feature%22)
 and found no similar feature requirement.
   
   
   ### Description
   
   You can just enable Dependabot to autogenerate PRs for jars that have 
security issues. There is another mode where Dependabot generates PRs for all 
new releases of dependenncies. The latter can be noisy but just enabling it for 
security issues would be very useful.
   
   I recently raised https://github.com/apache/incubator-streampark/pull/1548 
(and a few others) and I wouldn't have had to if Dependabot was enabled.
   
   
https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-supply-chain-security
   
   Dependabot can also scan your Github Actions for pipeline issues - 
https://docs.github.com/en/code-security/dependabot/working-with-dependabot/keeping-your-actions-up-to-date-with-dependabot
 
   
   ### Usage Scenario
   
   _No response_
   
   ### Related issues
   
   _No response_
   
   ### Are you willing to submit a PR?
   
   - [ ] Yes I am willing to submit a PR!
   
   ### Code of Conduct
   
   - [X] I agree to follow this project's [Code of 
Conduct](https://www.apache.org/foundation/policies/conduct)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to