File tree 1 file changed +16
-2
lines changed
170_supply_chain_security/renovate
1 file changed +16
-2
lines changed Original file line number Diff line number Diff line change @@ -68,7 +68,7 @@ Provides visibility
68
68
69
69
Can be matched against known vulnerabilities
70
70
71
- ### Auditing is the last resort
71
+ ### Evaluation is the last resort
72
72
73
73
Update dependencies quickly
74
74
@@ -222,6 +222,8 @@ Filter log for errors / failures for...
222
222
- Permission issues
223
223
- Rate limits
224
224
225
+ XXX open PRs
226
+
225
227
### Up-to-dateness
226
228
227
229
Failures will show in the log
@@ -287,14 +289,24 @@ Show updates addressing security alerts [](https://docs.renovatebot.com/configur
287
289
288
290
Integrates with GitHub and Dependabot
289
291
292
+ XXX new feature... open issue?
293
+
290
294
### Requirements
291
295
292
- Enable GitHub Dependency Grapg [ ] ( https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-the-dependency-graph#enabling-the-dependency-graph )
296
+ Enable GitHub Dependency Graph [ ] ( https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-the-dependency-graph#enabling-the-dependency-graph )
293
297
294
298
Enable alert from Dependabot [ ] ( https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-security-and-analysis-settings-for-your-repository )
295
299
296
300
---
297
301
302
+ ## Testing the Renovate configuration
303
+
304
+ XXX isolate change in separate repo
305
+
306
+ XXX ` --platform=local `
307
+
308
+ ---
309
+
298
310
## Alternatives
299
311
300
312
### Dependabot
@@ -315,6 +327,8 @@ Detailed comparison [](https://docs.renovatebot.com/bot-comparison/)
315
327
316
328
## Case study: uniget
317
329
330
+ XXX improve value proposition
331
+
318
332
### Installer and updater for (container) tools
319
333
320
334
Checkout uniget.dev [ ] ( https://uniget.dev )
You can’t perform that action at this time.
0 commit comments