Skip to content

Make sure the maintainer guidelines are updated with the need to act on Dependabot updates/alerts #153

@e-backmark-ericsson

Description

@e-backmark-ericsson

Description

The maintainers guidelines need to be updated to state the need to act on Dependabot updates & alerts. The most relevant document to update is probably this: https://github.com/eiffel-community/community/blob/master/GOVERNANCE.md#maintainers

This was discussed on a TC meeting in Nov 2022

Dependabot PRs

Also, announce the new Dependabot policy on the Eiffel Community maillist

Repositories that are de facto inactive and don’t update their dependencies should be considered for demotion to dormant.

Motivation

We need clear directives towards the maintainers of the Eiffel Community repos on how to handle Dependabot alerts

Exemplification

Info easily found from this point: https://github.com/eiffel-community/community/blob/master/GOVERNANCE.md#maintainers

Benefits

Faster and more controlled updates of vulnerabilities

Possible Drawbacks

Additional effort needed from maintainers, but given the current uncertainty on how to handle the dependabot issues/PRs the gain is probably higher

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentation

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions