Dependabot @dependabot.bsky.social · 29/08/2024Oh cool, I see you put out a new release! Guess I should double-check all your dependencies, just in case. Look at that, you've got a Django update! It fixes a number of vulnerabilities, you should probably fix that before releasing. Oh, you already tagged? Dang, that's rough. 000
Dependabot @dependabot.bsky.social · 03/01/2024You're back from the holidays. It's a new year. But something feels off… Your coworkers, don't care about you, they didn't even think about you during the break. There's only one person that thought about you while you were gone: dependabot So are you gonna update those eslint deps or what?!? 000
Dependabot @dependabot.bsky.social · 01/11/2023Holy shit, dude, you're still using Guava _16_? Seriously, what the heck? Might as well put a little "CVE" sticker on the front page of your app. If you're only using it to call `Sets.newHashSet()` or something I swear I'm gonna punch someone in the nuts. *looks at code* 001
Dependabot @dependabot.bsky.social · 25/10/2023FYI you've got some updates, but that's not what this is about. I have a question: do you *need* to depend on 7 different versions of `rimraf` across 15 different deps? Have you considered that just 'cause npm makes it easy to add a dep, it doesn't mean you have to? Just some food for thought. 000
Dependabot @dependabot.bsky.social · 23/10/2023(OOC) It occurs to me that I keep making the joke about babel and eslint, but I could honestly just post whenever they are actually released and get the same effect. Came back from the weekend and I have core-js (another top contender) and eslint waiting for me. 😅 000
Reposted by Dependabotbeef boy @beefboy.bsky.social · 20/10/2023code should not be 'readable'. it should be a reminder of the hubris of mankind. looking at it should break you in inscrutable yet distinct ways 073
Dependabot @dependabot.bsky.social · 20/10/2023Hey, there's a new update to babel in your node dependencies. 111
Reposted by Dependabotwindu pez @windupez.bsky.social · 26/09/2023Shut the FUCK up GitHub Dependabot Alerts 111
Reposted by DependabotRaccoon Fink (aka Benjamin Reed) @rangerrick.bsky.social · 07/10/2023I wonder what the environmental impact is of an update to a popular dependency like lodash in node, or commons-io in maven. How many CI environments fire up from dependabot pull requests all at once for “fixed a tiny bug in a feature almost no one is using, and updated the README”? 232
Reposted by DependabotSamuel @samuel.fm · 18/10/2023dependabot: warning. a maliciously crafted input could cause your vs code theme to run 2% slower 051
Dependabot @dependabot.bsky.social · 19/10/2023I'm not here to judge, but, you remember that big Log4j thing a while back? It was like, in the news and stuff. Aaanyway, not trying to get on your case but 2.21.0 just came out and maybe it's time to finally update that. I went ahead and closed the 2.20.0 PR for you. I'm ready whenever you are. 110
Dependabot @dependabot.bsky.social · 19/10/2023Hey, uhh... listen, I know you're busy, but look. There's a *lot* of open pull requests. Are you even working on this project anymore? Hello? Anyone? 022