Skip to content

Conversation

@daklauss
Copy link
Member

To avoid upgrading issues such as fau-advanced-separations/CADET-Process#229, we should consider adding something like dependabot to automatically manage our dependencies.

Dependabot would need enabled requirements in the security settings. Depending on the settings it is possible to automaticly detect and manage our dependencies. On the downside, it is not able to check for conda, only for dependabot/dependabot-core#2227 as ecosystem.

In the context of our current Issues, as far as i am understanding dependabot, it wouldn't have been able to detect fau-advanced-separations/CADET-Process#229 earlier or at all, because libsqlite 3.49.1 is not a direct dependency of our environments but comes automaticly with diskcache.

@ronald-jaepel ronald-jaepel merged commit 368700c into master Feb 26, 2025
6 checks passed
@hannahlanzrath hannahlanzrath deleted the add-dependabot branch July 29, 2025 10:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants