downshift-js / downshift-js/downshift

Scheduled dependency updates

Open
#1,644 1 comment 0 reactions 0 assignees View on GitHub
needs discussion
Dominant language
JavaScript
Stars
12.3k
Forks
936
PR merge metrics
No merged PRs in 30d

Description

**Problem Description**

To minimize security vulnerabilities, enabling Dependabot, Renovate or another alternative for scheduled dependency updates would be useful.

Since the `package-lock.json` file is not published, there's no way to verify dependencies have the upgraded.

**Potential Solution**

Enable Dependabot, Renovate or another alternative for scheduled dependency updates to enhance security and outdated dependencies.

Snyk is another option that can be considered as a developer security platform to help identify vulnerabilities in dependencies.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.