downshift-js / downshift-js/downshift
Scheduled dependency updates
Open
needs discussion
- Dominant language
- JavaScript
- Stars
- 12.3k
- Forks
- 936
- PR merge metrics
- No merged PRs in 30d
Description
**Problem Description**
To minimize security vulnerabilities, enabling Dependabot, Renovate or another alternative for scheduled dependency updates would be useful.
Since the `package-lock.json` file is not published, there's no way to verify dependencies have the upgraded.
**Potential Solution**
Enable Dependabot, Renovate or another alternative for scheduled dependency updates to enhance security and outdated dependencies.
Snyk is another option that can be considered as a developer security platform to help identify vulnerabilities in dependencies.
Contributor guide
Assessment
This issue has not been assessed yet.