googleapis / googleapis/google-cloud-node

Reconfigure renovate or add dependabot to make sure we get dependency PRs for known security vulnerabilities

Open
#7,711 2 comments 2 reactions 1 assignee Claimed by @sofisl View on GitHub
library: google-cloud-node-core priority: p3 size: m type: feature request
Dominant language
TypeScript
Stars
3.2k
Forks
712
Avg merge
2d 3h
Merged PRs (30d)
99

Description

Thanks for stopping by to let us know something could be better!

**Is your feature request related to a problem? Please describe.**

When this package has a vulnerable dependency, contributors need to manually open a PR and an issue to upgrade said dependencies.

**Describe the solution you'd like**

Setting up an automated system such as DependaBot would signifiicantly increase the QoL for contributors and users. It would also save time and increase security.

**Describe alternatives you've considered**

**Additional context**

You can find [a quickstart guide for DependaBot on Github Docs](https://docs.github.com/en/code-security/getting-started/dependabot-quickstart-guide).

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.