TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Dependabot is joining GitHub

215 pointsby reqresalmost 6 years ago

14 comments

the_dukealmost 6 years ago
Edit: copy&#x2F;pasting my more extensive comment from the Sponsors thread.<p>All the recent additions to Github are superficially very nice and convenient features (Actions, package registry, Sponsors, Dependabot).<p>But they represent a very significant change in mindset. Github is turning from a neutral code hosting platform with a myriad of equally empowered third party integrations into the direction of a &quot;all in one&quot; dev tool and platform.<p>I understand the internal pressures to do this: increased popularity, added value proposition for customers, more revenue.<p>But: all the built-in tools will have an inherent advantage over third party solutions. This inevitably leads to increased lock-in and homogenization.<p>I was very critical of the Microsoft acquisition for similar reasons, and considering the monumental role Github represents for open source today, I am very sceptical of the way things are going.<p>We might very well regret centralizing everything open source around Github in a few years.
评论 #19990650 未加载
评论 #19993384 未加载
评论 #19990315 未加载
评论 #19991348 未加载
评论 #19993876 未加载
评论 #19990591 未加载
评论 #20018608 未加载
评论 #19992350 未加载
评论 #19994092 未加载
评论 #19993912 未加载
threeseedalmost 6 years ago
Curious about the side effects of this.<p>Imagine you had an open source project that was just something on the side or you worked on in a different life. And then you see pull requests for updates and decide to fix a bug here or there. And then maybe it prompts you to recommit to it.<p>If that were to apply to even a tiny percentage across all of Github could have major implications for open source as a whole.
评论 #19989956 未加载
评论 #19990009 未加载
ValCanBuildalmost 6 years ago
Massive congrats to the team! Well deserved, Dependabot is an awesome tool!
评论 #19990842 未加载
ralphstodomingoalmost 6 years ago
Microsoft really is growing GitHub. I can&#x27;t say I&#x27;m not pleasantly surprised.
评论 #19990373 未加载
rvanmilalmost 6 years ago
Did GitHub just activate this without confirmation or notification? I&#x27;m suddenly receiving PR&#x27;s on my repo&#x27;s from dependabot without ever activating this tool.<p>Edit: looks like they defaulted to enable &quot;Automated security fixes&quot; on the Security &gt; Alerts tab.
coreyjaalmost 6 years ago
Congrats to the Dependabot team!<p>I&#x27;ve had the pleasure of reaching out to Dependabot a few times when I&#x27;ve had issues or problems and you guys have always been super responsive and quick to fix any bugs!<p>Congrats again on joining Github! And excited to see whats next for Dependabot!
craze3almost 6 years ago
Congrats guys! For anyone interested, here&#x27;s an interview on how Dependabot started: <a href="https:&#x2F;&#x2F;www.indiehackers.com&#x2F;interview&#x2F;living-off-our-savings-and-growing-our-saas-to-740-mo-696f9b110f" rel="nofollow">https:&#x2F;&#x2F;www.indiehackers.com&#x2F;interview&#x2F;living-off-our-saving...</a>
muhgarveyalmost 6 years ago
Congratulations! We&#x27;re very happy with our Dependabot use and hope it helps the community
floor_almost 6 years ago
Anyone else remember that whitespace bot that spammed everyone&#x27;s repos? Last thing we need are more bots clogging our code shitters.
illnewsthatalmost 6 years ago
Can anyone recommend a tool similar to Dependabot that works with bitbucket?
jhuckesteinalmost 6 years ago
Massive congrats to the team - what a great and well deserved outcome :)
dm7almost 6 years ago
congrats!
jeffshekalmost 6 years ago
Huge congrats to Dependabot team! If you&#x27;re starting a new project in Python (+ others), having Dependabot + CircleCI (or something equivalent) + Strong test coverage will save you hundreds of hours (eventually).<p>Best trick is to make sure your test coverage is strong early (I know this is easier said than done ...), then you can just merge updated requirements without ever worrying.<p>GitHub has a type of service that would check requirements already, it just never felt as polished as Dependabot. But it goes to show how far a committed team can prioritize over bigger players. IIRC, they still use Heroku, which seems like a lot of discipline in prioritizing the right product features over just building tech stacks in BigCloudProviders.
评论 #19990951 未加载
stephensonalmost 6 years ago
That makes so much sense! A more secure open source world, a better product for our close projects and two amazing tools merging. Love it!<p>Dependabot, you did well, build a fantastic tool, now join the rocketship and kick ass!
评论 #19994103 未加载