We just use dependabot to issue PRs for updating dependencies, and we merge automatically when tests pass. It's never caused an issue.
It works great but the underlying problem still remains I guess
We just use dependabot to issue PRs for updating dependencies, and we merge automatically when tests pass. It's never caused an issue.