TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Dependabot is joining GitHub

215 点作者 reqres将近 6 年前

14 条评论

the_duke将近 6 年前
Edit: copy&#x2F;pasting my more extensive comment from the Sponsors thread.<p>All the recent additions to Github are superficially very nice and convenient features (Actions, package registry, Sponsors, Dependabot).<p>But they represent a very significant change in mindset. Github is turning from a neutral code hosting platform with a myriad of equally empowered third party integrations into the direction of a &quot;all in one&quot; dev tool and platform.<p>I understand the internal pressures to do this: increased popularity, added value proposition for customers, more revenue.<p>But: all the built-in tools will have an inherent advantage over third party solutions. This inevitably leads to increased lock-in and homogenization.<p>I was very critical of the Microsoft acquisition for similar reasons, and considering the monumental role Github represents for open source today, I am very sceptical of the way things are going.<p>We might very well regret centralizing everything open source around Github in a few years.
评论 #19990650 未加载
评论 #19993384 未加载
评论 #19990315 未加载
评论 #19991348 未加载
评论 #19993876 未加载
评论 #19990591 未加载
评论 #20018608 未加载
评论 #19992350 未加载
评论 #19994092 未加载
评论 #19993912 未加载
threeseed将近 6 年前
Curious about the side effects of this.<p>Imagine you had an open source project that was just something on the side or you worked on in a different life. And then you see pull requests for updates and decide to fix a bug here or there. And then maybe it prompts you to recommit to it.<p>If that were to apply to even a tiny percentage across all of Github could have major implications for open source as a whole.
评论 #19989956 未加载
评论 #19990009 未加载
ValCanBuild将近 6 年前
Massive congrats to the team! Well deserved, Dependabot is an awesome tool!
评论 #19990842 未加载
ralphstodomingo将近 6 年前
Microsoft really is growing GitHub. I can&#x27;t say I&#x27;m not pleasantly surprised.
评论 #19990373 未加载
rvanmil将近 6 年前
Did GitHub just activate this without confirmation or notification? I&#x27;m suddenly receiving PR&#x27;s on my repo&#x27;s from dependabot without ever activating this tool.<p>Edit: looks like they defaulted to enable &quot;Automated security fixes&quot; on the Security &gt; Alerts tab.
coreyja将近 6 年前
Congrats to the Dependabot team!<p>I&#x27;ve had the pleasure of reaching out to Dependabot a few times when I&#x27;ve had issues or problems and you guys have always been super responsive and quick to fix any bugs!<p>Congrats again on joining Github! And excited to see whats next for Dependabot!
craze3将近 6 年前
Congrats guys! For anyone interested, here&#x27;s an interview on how Dependabot started: <a href="https:&#x2F;&#x2F;www.indiehackers.com&#x2F;interview&#x2F;living-off-our-savings-and-growing-our-saas-to-740-mo-696f9b110f" rel="nofollow">https:&#x2F;&#x2F;www.indiehackers.com&#x2F;interview&#x2F;living-off-our-saving...</a>
muhgarvey将近 6 年前
Congratulations! We&#x27;re very happy with our Dependabot use and hope it helps the community
floor_将近 6 年前
Anyone else remember that whitespace bot that spammed everyone&#x27;s repos? Last thing we need are more bots clogging our code shitters.
illnewsthat将近 6 年前
Can anyone recommend a tool similar to Dependabot that works with bitbucket?
jhuckestein将近 6 年前
Massive congrats to the team - what a great and well deserved outcome :)
dm7将近 6 年前
congrats!
jeffshek将近 6 年前
Huge congrats to Dependabot team! If you&#x27;re starting a new project in Python (+ others), having Dependabot + CircleCI (or something equivalent) + Strong test coverage will save you hundreds of hours (eventually).<p>Best trick is to make sure your test coverage is strong early (I know this is easier said than done ...), then you can just merge updated requirements without ever worrying.<p>GitHub has a type of service that would check requirements already, it just never felt as polished as Dependabot. But it goes to show how far a committed team can prioritize over bigger players. IIRC, they still use Heroku, which seems like a lot of discipline in prioritizing the right product features over just building tech stacks in BigCloudProviders.
评论 #19990951 未加载
stephenson将近 6 年前
That makes so much sense! A more secure open source world, a better product for our close projects and two amazing tools merging. Love it!<p>Dependabot, you did well, build a fantastic tool, now join the rocketship and kick ass!
评论 #19994103 未加载