client_golang icon indicating copy to clipboard operation
client_golang copied to clipboard

Configure security vuln dependabot automation for latest image.

Open bwplotka opened this issue 1 year ago • 4 comments

I think https://github.com/prometheus/client_golang/security/dependabot works great, but it's easy to forget we might have NOT released those patches on the latest release. Let's make sure we are notified/dependabot ports patches.

See https://github.com/prometheus/client_golang/pull/1494

bwplotka avatar May 09 '24 11:05 bwplotka

Hey @bwplotka, I noticed that Dependabot only updates the default branch for security patches. Do we open to switch to Renovate? the later is used in Mimir, and it handles multiple branches better and seems more flexible. wdyt, or do you have another idea in mind?

ying-jeanne avatar Sep 16 '24 12:09 ying-jeanne

Whatever works! (:

bwplotka avatar Sep 16 '24 16:09 bwplotka

If we move forward with renovate, I'd love to see this workflow still working 🙈. It currently depends on the github action dependabot/fetch-metadata, not sure how this works with renovate

ArthurSens avatar Sep 17 '24 08:09 ArthurSens

Hello 👋 Looks like there was no activity on this issue for the last 3 months. Do you mind updating us on the status? Is this still reproducible or needed? If yes, just comment on this PR or push a commit. Thanks! 🤗 If there will be no activity in the next 4 weeks, this issue will be closed (we can always reopen an issue if we need!).

stale[bot] avatar Jul 19 '25 06:07 stale[bot]