coinbase / coinbase/mongobetween

Update numerous dependencies

Open
#82 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
167
Forks
70
PR merge metrics
No merged PRs in 30d

Description

I have a fork of this repo (basically just slapping a Dockerfile on top). In my fork, default security vulnerabilities checks are enabled and there are a few critical ones and a bunch of others, due to numerous dependencies being out of date.

Does this repo still have a maintainer? It would be nice if they bumped all (at least security impacting) deps to their latest (or safe) versions. Some of the auto-generated dependabot PRs in my fork actually break tests so at least some of the upgrades require expertise in the codebase. I'm not a golang developer and thus don't feel like I can do justice to this task myself.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the Dockerfile and the existing auto-generated Dependabot PRs, then run the repository's tests to identify which upgrades break them. Done means addressing the critical and other security-impacting dependency vulnerabilities while keeping the test suite passing, but the issue does not identify specific dependency files or tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
devops, security
Issue type
Refactor
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.