TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Dependabot is now free

158 pointsby colinbartlettalmost 6 years ago

11 comments

nullandvoidalmost 6 years ago
For anyone wanting this functionality directly in the editor and is working with npm &#x2F; vs code i&#x27;ve found this extension to be great <a href="https:&#x2F;&#x2F;marketplace.visualstudio.com&#x2F;items?itemName=pflannery.vscode-versionlens" rel="nofollow">https:&#x2F;&#x2F;marketplace.visualstudio.com&#x2F;items?itemName=pflanner...</a><p>( no affiliation just a happy user )
detaroalmost 6 years ago
recent (4 days ago) discussion of the aquisition: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=19989631" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=19989631</a>
Cogitrialmost 6 years ago
I&#x27;ve been using Dependabot (for free) for my Rust projects for the last months, it really is nice.
pbiggaralmost 6 years ago
Excellent marketing! I checked out the author&#x27;s product, Statusgator, and signed up for a $30&#x2F;mo plan. It aggregates statuspages of all the vendors we use, and pings our slack channel. Super useful!
CraftThatBlockalmost 6 years ago
What&#x27;s the difference vs Greenkeeper?
评论 #20018467 未加载
评论 #20018130 未加载
derkoealmost 6 years ago
<a href="https:&#x2F;&#x2F;renovatebot.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;renovatebot.com&#x2F;</a> is open source and supports more dependency management systems
latchkeyalmost 6 years ago
&gt; &quot;Microsoft, the richest public company in the world&quot;<p>Not even the top 15 [1], they are 16th.<p>[1] <a href="https:&#x2F;&#x2F;www.forbes.com&#x2F;global2000" rel="nofollow">https:&#x2F;&#x2F;www.forbes.com&#x2F;global2000</a>
评论 #20020526 未加载
kimatalmost 6 years ago
<a href="https:&#x2F;&#x2F;github.com&#x2F;sanemat&#x2F;tachikoma" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;sanemat&#x2F;tachikoma</a>
matthewbaueralmost 6 years ago
I don’t understand why we need these tools when we use semver? The semver range should be flexible enough to handle the nonbreaking changes. You definitely don’t want a bot updating breaking changes of dependencies automatically, unless you like breaking things. That’s the kind of thing that should require manual intervention for.
评论 #20018704 未加载
评论 #20018846 未加载
评论 #20018727 未加载
评论 #20018679 未加载
评论 #20019058 未加载
评论 #20019620 未加载
BubRossalmost 6 years ago
I wish we could do away with the clickbait nonsense headline editorializing.
评论 #20018215 未加载
Animatsalmost 6 years ago
<i>Setup and installation is simple: a quick sign up with GitHub OAuth was all that was required, along with a grant to read and write code in our repositories.</i><p>Why does it need permissions to read and write code? If it&#x27;s a public repository, anyone can read. It shouldn&#x27;t be modifying code. At best it should be submitting patch requests.<p>Giving Microsoft write permission on open source code is dangerous. They might decide that they need to inject &quot;telemetry&quot;. As they&#x27;ve done to non-Microsoft applications on Windows.
评论 #20019238 未加载
评论 #20019235 未加载