Disabling Scheduled Dependency Updates

18 pointsposted a year ago
by benhoyt

4 Comments

ydnaclementine

a year ago

This guy calls it out here, but I will say that the notifications page on github could do with a redesign. If you're in a busy org for your job, it's not easy to see everything in the org (they limit showing number of notifications per repo), and the volume of notifications from your job org will cover up anything in your personal/following repos.

Sure you could unfollow work repos you aren't interested in, but you're automatically following any new ones.

cesnja

a year ago

You get to choose either the mind-numbing churn of constant updates, the risk of updates piling up and becoming unmanageable, or shipping software with vulnerabilities. None of these options sounds fun.

donatj

a year ago

I really wish there was a step before opening a PR, like a page with a list of what's out of date that let's you click a button to open a PR for one or more dependency updates.