4 ms·
Same feelings. I like the idea but in practice I don’t trust it. Or rather, I don’t trust package maintainers to adhere to semver. I prefer to manually go thro
by ncphillips 4y ago
Same feelings. I like the idea but in practice I don’t trust it.
Or rather, I don’t trust package maintainers to adhere to semver. I prefer to manually go through dependencies updating one at a time and reading the change logs. I usually do this in batch. Peace of mind is worth more than the hour saved every week or two.
I do really like the tool that flags security issues with packages though.
- hypeatei 4y agoThis is what I do, too. Dependabot creates the PRs and I review the changelog / commits to make sure I'm not introducing a bug or security issue.
- aeyes 4y agoYou can still use dependabot to assist you with this. Let it only open PRs and it will show you the commits and changelog or at least a link to the source project in the PR description. Having a PR already open with a full test run done in CI saves a ton of time, at least in repos with a lot of dependencies.