Update dependabot config#22111
Conversation
We only bump indirect depenencies in case there's a vulnerability reported. Refer to our [Dependency management](https://github.com/etcd-io/etcd/blob/main/Documentation/contributor-guide/dependency_management.md) documentation. However, Dependabot security updates is enabled for the repository. Therefore, Dependabot will still bump indirect dependencies with vulneratbilities even with the weekly version updates is turned off. Signed-off-by: Ivan Valdes <ivan@vald.es>
Signed-off-by: Ivan Valdes <ivan@vald.es>
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: ivanvc The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
@ivanvc: The following tests failed, say
Full PR test history. Your PR dashboard. Please help us cut down on flakes by linking to an open issue when you hit one in your PR. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted filessee 19 files with indirect coverage changes @@ Coverage Diff @@
## main #22111 +/- ##
==========================================
- Coverage 69.73% 69.64% -0.09%
==========================================
Files 449 449
Lines 38177 38177
==========================================
- Hits 26624 26590 -34
- Misses 10123 10155 +32
- Partials 1430 1432 +2 Continue to review full report in Codecov by Harness.
🚀 New features to boost your workflow:
|
Follow up on #22093 (comment)