rmannibucau commented on pull request #5: URL: https://github.com/apache/commons-weaver/pull/5#issuecomment-798869333
From what i see, dependabot has more false positives than benefits, in particular for commons projects so not sure it makes sense to bulk enable it like that. Upgrades are often a prerelease review task where project knowledge helps to pick relevant ones only. Just my 2 cts ---------------------------------------------------------------- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. For queries about this service, please contact Infrastructure at: [email protected]
