Skip to content

Getting some help with dependency management#1272

Closed
antoniovazquezblanco wants to merge 1 commit intovanniktech:mainfrom
antoniovazquezblanco:deps
Closed

Getting some help with dependency management#1272
antoniovazquezblanco wants to merge 1 commit intovanniktech:mainfrom
antoniovazquezblanco:deps

Conversation

@antoniovazquezblanco
Copy link
Copy Markdown

Hi there!

I've been using your plugin lately. I have some issues with some of your dependencies not being up to date and some of them having vulnerabilities...

imagen

Having a look at the repo it seems that you are managing the dependencies thing all by yourself and thought that maybe a little dependabot help would be reasonable...

For this to work, I think you have to go to your repo "Settings > Advanced Security > Dependabot" and enable dependabot there...

I would also recommend you enable 'Private vulnerability reporting' and the 'Dependency graph'.

If you are interested in me trying to setup some code scanning I can provide you with an adequate pipeline in another PR. Just let me know if you would like that...

This should help a little bit with security in general. Hope it helps :)


  • CHANGELOG's "Unreleased" section has been updated, if applicable.

@Goooler
Copy link
Copy Markdown
Contributor

Goooler commented Dec 17, 2025

Don't use @dependabot, there is a @renovate-bot setup.

Okhttp has been updated by #1209.

@antoniovazquezblanco
Copy link
Copy Markdown
Author

Makes sense. Did not know about that. Closing.

Maybe automatic dependency submission and private vuln reporting makes sense anyways to enable so that we can track those things directly from this repo.

Thank you!

@Goooler
Copy link
Copy Markdown
Contributor

Goooler commented Dec 17, 2025

It's intended to avoid updating Okhttp, see more details in #1131.

@antoniovazquezblanco
Copy link
Copy Markdown
Author

I totally get that it is intended to avoid updating it. I will open a new issue to propose another topic.

@Goooler
Copy link
Copy Markdown
Contributor

Goooler commented Dec 21, 2025

Succeeded by #1282.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants