Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm sure you have a lived experience that guides what you said, but this just hasnt been my experience.

We just use dependabot to issue PRs for updating dependencies, and we merge automatically when tests pass. It's never caused an issue.



I actually have dependabot enabled on a side project that I've stopped maintaining and every once in a while I get package update notifications.

It works great but the underlying problem still remains I guess




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: