RockPaperScissorsLizardSpock icon indicating copy to clipboard operation
RockPaperScissorsLizardSpock copied to clipboard

Resolves: Add native GitHub security and versioning dependency alerts

Open aleks-ivanov opened this issue 3 years ago • 0 comments

  • add dependabot.yml which automatically enables Dependabot's dependency versioning scanner and dependency update PRs bot by declaring dependency ecosystems and sources in the project. For dependency security vulnerabilities scanner and vulnerable dependency update PRs bot, enable "Dependabot alerts" and "Dependabot security updates"

  • should you decide that certain people on your team should take care of the PRs that Dependabot creates, use the two attributes assignees and reviewers to automatically set personnel respectively.

Resolves #43

aleks-ivanov avatar May 26 '21 14:05 aleks-ivanov