Comment by catlifeonmars
7 days ago
I use a dependabot config that buckets security updates into a separate pull than other updates. The non-security update PRs are just informational (can disable but I choose to leave them on), and you can actually spend the time to vet the security updates
No comments yet
Contribute on Hacker News ↗