A dozen Dependabot pull requests on a Monday morning is how important updates get ignored. On Microsoft's GCToolkit, roughly one in six commits were single-dependency version bumps.
Three small changes to dependabot.yml fixed it 👇
https://github.blog/security/supply-chain-security/tame-dependabot-group-your-updates-slow-the-cadence-keep-security-fast/
205
35
在 X 上查看 →