social.tchncs.de is one of the many independent Mastodon servers you can use to participate in the fediverse.
A friendly server from Germany – which tends to attract techy people, but welcomes everybody. This is one of the oldest Mastodon instances.

Administered by:

Server stats:

3.8K
active users

#dependabot

2 posts2 participants0 posts today
Josh Justice<p>And another happy <a href="https://tdd.social/tags/dependabot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dependabot</span></a> monthly updates day to those who celebrate!</p>
Nikita Karamov<p>At this point <a href="https://fosstodon.org/tags/Vite" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Vite</span></a> should just throw their dev server away or expose it as an additional package. I'm tired of all those <a href="https://fosstodon.org/tags/Dependabot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Dependabot</span></a> MRs fixing the sEcUrItY vUlNeRaBiLiTiEs</p><p>"Only apps explicitly exposing the Vite dev server to the network are affected" well yeah cause you're not supposed to do it 😩</p>
Alessandro Lai<p>If you're using <a href="https://phpc.social/tags/dependabot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dependabot</span></a> with a <a href="https://phpc.social/tags/php" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>php</span></a> library that still supports 7.4, it doesn't work now.</p><p>This is due to them ditching 7.4 with this PR: <a href="https://github.com/dependabot/dependabot-core/issues/6527" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/dependabot/dependab</span><span class="invisible">ot-core/issues/6527</span></a></p><p>I can understand pushing for the upgrade due to 7.4 being EOL, but that was a silent failure that I wasn't expecting. Also, if I'm not actively dropping support i.e. because it doesn't cost me anything in maintenace, I'm stuck.</p>
David Guillot<p>🚀 Great news for <a href="https://social.tchncs.de/tags/python" class="mention hashtag" rel="tag">#<span>python</span></a> developers! <a href="https://social.tchncs.de/tags/dependabot" class="mention hashtag" rel="tag">#<span>dependabot</span></a> now supports <a href="https://social.tchncs.de/tags/uv" class="mention hashtag" rel="tag">#<span>uv</span></a> <a href="https://social.tchncs.de/tags/astraluv" class="mention hashtag" rel="tag">#<span>astraluv</span></a> . Nothing stands between your codebase and almost-instant <a href="https://social.tchncs.de/tags/dependencymanagement" class="mention hashtag" rel="tag">#<span>dependencymanagement</span></a>!</p><p><a href="https://github.blog/changelog/2025-03-13-dependabot-version-updates-now-support-uv-in-general-availability/" target="_blank" rel="nofollow noopener noreferrer" translate="no"><span class="invisible">https://</span><span class="ellipsis">github.blog/changelog/2025-03-</span><span class="invisible">13-dependabot-version-updates-now-support-uv-in-general-availability/</span></a></p>
Chris is.<p>If you're not following it closely, you might have missed that <a href="https://wandering.shop/tags/uv" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>uv</span></a> support in <a href="https://wandering.shop/tags/dependabot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dependabot</span></a> is now available in beta: <a href="https://github.com/dependabot/dependabot-core/issues/10478#issuecomment-2691330949" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/dependabot/dependab</span><span class="invisible">ot-core/issues/10478#issuecomment-2691330949</span></a></p><p><a href="https://wandering.shop/tags/Python" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Python</span></a></p>
viq<p>Running <a href="https://social.hackerspace.pl/tags/Authentik" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Authentik</span></a> with `latest` tag was convenient for <a href="https://social.hackerspace.pl/tags/homelab" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>homelab</span></a>, but they're moving away from making it possible (edit: from having :latest tag available, nothing else changes). What are the alternatives? Is there maybe something like "<a href="https://social.hackerspace.pl/tags/dependabot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dependabot</span></a> but for <a href="https://social.hackerspace.pl/tags/kubernetes" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>kubernetes</span></a> images"? (I'm currently running on <a href="https://social.hackerspace.pl/tags/podman" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>podman</span></a> on nixos, but I'm considering finally playing with <a href="https://social.hackerspace.pl/tags/k8s" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>k8s</span></a>, and regardless, this should be able to make it so I have proper image on nixos as well, I think)</p>
LavX News<p>Dependabot Drops Support for Python 3.8: What Developers Need to Know</p><p>In a significant shift for Python developers, Dependabot has officially ceased support for Python 3.8 as of February 5, 2025. This change underscores the importance of keeping up with language updates...</p><p><a href="https://news.lavx.hu/article/dependabot-drops-support-for-python-3-8-what-developers-need-to-know" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">news.lavx.hu/article/dependabo</span><span class="invisible">t-drops-support-for-python-3-8-what-developers-need-to-know</span></a></p><p><a href="https://mastodon.cloud/tags/news" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>news</span></a> <a href="https://mastodon.cloud/tags/tech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tech</span></a> <a href="https://mastodon.cloud/tags/SoftwareSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SoftwareSecurity</span></a> <a href="https://mastodon.cloud/tags/Dependabot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Dependabot</span></a> <a href="https://mastodon.cloud/tags/Python3" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Python3</span></a></p>
James :ruby:<p>&gt; Dependabot security updates may include compatibility scores to let you know whether updating a dependency could cause breaking changes to your project. These are calculated from CI tests in other public repositories where the same security update has been generated. An update's compatibility score is the percentage of CI runs that passed when updating between specific versions of the dependency.</p><p>😍</p><p><a href="https://docs.github.com/en/code-security/dependabot/dependabot-security-updates/about-dependabot-security-updates#about-compatibility-scores" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">docs.github.com/en/code-securi</span><span class="invisible">ty/dependabot/dependabot-security-updates/about-dependabot-security-updates#about-compatibility-scores</span></a></p><p>Thanks to <span class="h-card" translate="no"><a href="https://hachyderm.io/@richardTowers" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>richardTowers</span></a></span>! 🙌</p><p><a href="https://ruby.social/tags/github" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>github</span></a> <a href="https://ruby.social/tags/dependabot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dependabot</span></a> <a href="https://ruby.social/tags/ruby" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ruby</span></a></p>
James :ruby:<p>Before they got taken over by GitHub, Dependabot used to provide a dashboard for each package. This dashboard displayed how many successful &amp; failing CI builds of dependent projects *using* the package there had been for each version of the package.</p><p>This gave an admittedly imperfect, but nevertheless useful, indication of the quality of each package release.</p><p>Does this still exist somewhere...?</p><p><a href="https://ruby.social/tags/ruby" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ruby</span></a> <a href="https://ruby.social/tags/dependabot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dependabot</span></a> <a href="https://ruby.social/tags/github" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>github</span></a></p>
Olivier Forget<p>FYI <a href="https://social.tchncs.de/tags/Github" class="mention hashtag" rel="tag">#<span>Github</span></a> <a href="https://social.tchncs.de/tags/Dependabot" class="mention hashtag" rel="tag">#<span>Dependabot</span></a> flags that <a href="https://social.tchncs.de/tags/Go" class="mention hashtag" rel="tag">#<span>Go</span></a> crypto <a href="https://social.tchncs.de/tags/vulnerability" class="mention hashtag" rel="tag">#<span>vulnerability</span></a> in your project even if you aren&#39;t affected. It checks if you import the package, not if you actually use the affected functions. govulncheck does it correctly.</p><p>Lucky for me that means I don&#39;t have to change anything in my project.</p><p>Thanks to <span class="h-card" translate="no"><a href="https://abyssdomain.expert/@filippo" class="u-url mention">@<span>filippo</span></a></span></p>
Alvin Ashcraft 🐿️<p>Using Dependabot to Manage .NET SDK Updates.</p><p><a href="https://buff.ly/3B5F6eD" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">buff.ly/3B5F6eD</span><span class="invisible"></span></a> <br><a href="https://hachyderm.io/tags/dotnet" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dotnet</span></a> <a href="https://hachyderm.io/tags/dependabot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dependabot</span></a> <a href="https://hachyderm.io/tags/dependencies" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dependencies</span></a> <a href="https://hachyderm.io/tags/updates" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>updates</span></a></p>
postmodern<p>Is there a way to configure dependabot to ignore other test fixture Gemfile.lock files that are stored in spec/?<br><a href="https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">docs.github.com/en/code-securi</span><span class="invisible">ty/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file</span></a></p><p><a href="https://ruby.social/tags/dependabot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dependabot</span></a></p>
Anders Eknert<p>Configuring <a href="https://hachyderm.io/tags/GitHub" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHub</span></a>'s <a href="https://hachyderm.io/tags/dependabot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dependabot</span></a> to run at a scheduled interval, and to group all PR's into a single one... is such a massive time saver for anyone maintaining a large number of repos. Or even just a few npm repos, lol. Make sure to do that!</p><p><a href="https://gist.github.com/anderseknert/61525b108a4c3406a7a67d62edbeafe1" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">gist.github.com/anderseknert/6</span><span class="invisible">1525b108a4c3406a7a67d62edbeafe1</span></a></p><p><a href="https://hachyderm.io/tags/OpenSource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenSource</span></a> <a href="https://hachyderm.io/tags/Development" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Development</span></a></p>
Romain Tartière<p>I am looking for help with <a href="https://mamot.fr/tags/github" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>github</span></a> and <a href="https://mamot.fr/tags/dependabot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dependabot</span></a>.</p><p>I am puzzled by how dependabot generate PRs for updates to dependencies of a <a href="https://mamot.fr/tags/ruby" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ruby</span></a> project.</p><p>Take this PR which is supposed to update rubocop: it also bump json version. But rubocop does NOT depend on this new version of json so why is it part of the same PR?</p><p><a href="https://github.com/opus-codium/pakotoa/pull/233/files" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/opus-codium/pakotoa</span><span class="invisible">/pull/233/files</span></a></p><p>Is there some setting we can use to stop this insanity? The docs seems to scream that it does what I want it to do, but in reality I don't observe this.</p>
Dennis Doomen<p>But here's an even better option: move your code to GitHub and take advantage of <a href="https://mastodon.social/tags/Dependabot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Dependabot</span></a>. This feature automatically detects which packages need updates and creates pull requests to handle them. It even includes relevant release notes and information on the risk level of updates based on similar attempts from the community.</p>
David Cantrell 🏏<p><a href="https://fosstodon.org/tags/Github" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Github</span></a> are idiots. Their <a href="https://fosstodon.org/tags/dependabot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dependabot</span></a> has been moaning at me because some of my workflows use 'download-artifact@v4'. Apparently version 4.1.6 of that has some security oopsie, but by the time they notified me version 4.1.7 was out, and so my workflow should have been using that and there was nothing to fix. 1/4</p>
Neil Craig<p>If you're seeing Dependabot PRs on Node projects named "Bump find-my-way and fastify" today and were not already on Fastify v5, be aware you'll need to update your Fastify config/usage (see <a href="https://fastify.dev/docs/latest/Guides/Migration-Guide-V5" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">fastify.dev/docs/latest/Guides</span><span class="invisible">/Migration-Guide-V5</span></a>).</p><p>The `find-my-way` (indirect for me) update requires Fastify v5 apparently and that broke several projects which weren't on Fastify v5 yet. Luckily (well, intentionally, obv) the breakages were caught by CICD in dev.</p><p><a href="https://mastodon.social/tags/Node" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Node</span></a> <a href="https://mastodon.social/tags/Fastify" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Fastify</span></a> <a href="https://mastodon.social/tags/FindMyWay" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FindMyWay</span></a> <a href="https://mastodon.social/tags/Dependabot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Dependabot</span></a></p>
David Lord :python:<p>I created a new tool, gha-update, to update GitHub Actions pins in workflows to the latest versions, using commit hashes and tag comments. I've wanted to move away from monthly Dependabot updates, 3 pages of notifications at the beginning of each month, many for low activity/stable projects, is way too noisy. <a href="https://github.com/davidism/gha-update" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">github.com/davidism/gha-update</span><span class="invisible"></span></a> <a href="https://mas.to/tags/Python" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Python</span></a> <a href="https://mas.to/tags/GitHub" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHub</span></a> <a href="https://mas.to/tags/Dependabot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Dependabot</span></a></p>
Robin Osborne<p>I thought it might be FUN to finally get around to the <a href="https://hachyderm.io/tags/dependabot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dependabot</span></a> emails I've been getting for years, prompting me to update my public <a href="https://hachyderm.io/tags/github" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>github</span></a> repos, so I decided to write up the process.</p><p>I'm on the *first repo*, 1500+ words and 20+ images in, and I haven't even got it building yet.</p><p>Seem that <a href="https://hachyderm.io/tags/Azure" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Azure</span></a> has changed a bit in the decade+ since I wrote that repo. Maybe this isn't going to be as much fun as I hoped...</p><p><a href="https://hachyderm.io/tags/webdev" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>webdev</span></a> <a href="https://hachyderm.io/tags/coding" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>coding</span></a></p>
Foojay.io<p>Did you know? You can configure <a href="https://foojay.social/tags/Renovate" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Renovate</span></a> for every package manager you can think of. Even better, Renovate allows the contribution of new package managers, contrary to <a href="https://foojay.social/tags/Dependabot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Dependabot</span></a>. <span class="h-card" translate="no"><a href="https://mastodon.top/@frankel" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>frankel</span></a></span> shares the details on Foojay :foojay: Today!</p><p><a href="https://foojay.io/today/renovate-for-everything/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">foojay.io/today/renovate-for-e</span><span class="invisible">verything/</span></a></p><p><a href="https://foojay.social/tags/foojaytip" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>foojaytip</span></a></p>