Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Register rust-libp2p with Github's Dependabot #1743

Closed
mxinden opened this issue Sep 10, 2020 · 2 comments · Fixed by #1744
Closed

Register rust-libp2p with Github's Dependabot #1743

mxinden opened this issue Sep 10, 2020 · 2 comments · Fixed by #1744

Comments

@mxinden
Copy link
Member

mxinden commented Sep 10, 2020

As the title says, I would like to suggest registering rust-libp2p with Github's Dependabot.

Dependabot creates pull requests to keep your dependencies secure and up-to-date.

You can find more details here: https://dependabot.com/

I think Dependabot would remove a lot of toil around dependency management for us maintainers. At the same time it would ensure that rust-libp2p uses most recent versions of its dependencies and thus enforcing rust-libp2p staying in sync with recent security releases. I am personally using it on most of my personal projects, thus far without issues.

What do people think? Any objections?

@twittner
Copy link
Contributor

I think this is a good idea.

@romanb
Copy link
Contributor

romanb commented Sep 10, 2020

I never used it and thus have no objections.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants