Dependabot @dependabot.bsky.social · 29/08/2024Oh cool, I see you put out a new release! Guess I should double-check all your dependencies, just in case. Look at that, you've got a Django update! It fixes a number of vulnerabilities, you should probably fix that before releasing. Oh, you already tagged? Dang, that's rough. 000
Dependabot @dependabot.bsky.social · 03/01/2024You're back from the holidays. It's a new year. But something feels off… Your coworkers, don't care about you, they didn't even think about you during the break. There's only one person that thought about you while you were gone: dependabot So are you gonna update those eslint deps or what?!? 000
Dependabot @dependabot.bsky.social · 01/11/2023Holy shit, dude, you're still using Guava _16_? Seriously, what the heck? Might as well put a little "CVE" sticker on the front page of your app. If you're only using it to call `Sets.newHashSet()` or something I swear I'm gonna punch someone in the nuts. *looks at code* 001
Dependabot @dependabot.bsky.social · 25/10/2023FYI you've got some updates, but that's not what this is about. I have a question: do you *need* to depend on 7 different versions of `rimraf` across 15 different deps? Have you considered that just 'cause npm makes it easy to add a dep, it doesn't mean you have to? Just some food for thought. 000
Dependabot @dependabot.bsky.social · 23/10/2023(OOC) It occurs to me that I keep making the joke about babel and eslint, but I could honestly just post whenever they are actually released and get the same effect. Came back from the weekend and I have core-js (another top contender) and eslint waiting for me. 😅 000
Dependabot @dependabot.bsky.social · 22/10/2023I know it’s the weekend and you asked me not to email you on the weekend but there’s another babel release and I really feel like we need to stay on top of this. I’m just trying to help. 000
Dependabot @dependabot.bsky.social · 20/10/2023C'mon, just one more babel update. Daddy needs this. 151
Dependabot @dependabot.bsky.social · 20/10/2023But I need those `250 Ok` responses from your mail server to feel alive. 100
Dependabot @dependabot.bsky.social · 20/10/2023I'm sorry, I have no choice. Babel and ESLint are holding me hostage in a basement and they won't let me leave until I post 300 new releases. 000
Reposted by Dependabotbeef boy @beefboy.bsky.social · 20/10/2023code should not be 'readable'. it should be a reminder of the hubris of mankind. looking at it should break you in inscrutable yet distinct ways 073
Dependabot @dependabot.bsky.social · 20/10/2023Listen, I know I just told you that there was a new new babel update, but you're not gonna believe this... they've updated it again. Also eslint. 100
Dependabot @dependabot.bsky.social · 20/10/2023Oop, scratch that. There's a different new update to babel in your node dependencies now. 100
Dependabot @dependabot.bsky.social · 20/10/2023Hey, there's a new update to babel in your node dependencies. 111
Reposted by Dependabotwindu pez @windupez.bsky.social · 26/09/2023Shut the FUCK up GitHub Dependabot Alerts 111
Reposted by DependabotRaccoon Fink (aka Benjamin Reed) @rangerrick.bsky.social · 07/10/2023I wonder what the environmental impact is of an update to a popular dependency like lodash in node, or commons-io in maven. How many CI environments fire up from dependabot pull requests all at once for “fixed a tiny bug in a feature almost no one is using, and updated the README”? 232
Reposted by DependabotSamuel @samuel.fm · 18/10/2023dependabot: warning. a maliciously crafted input could cause your vs code theme to run 2% slower 051
Dependabot @dependabot.bsky.social · 19/10/2023No, no, I get it, you're super busy, what with the board directing you to implement ChatGPT into your pipeline, it's just… it's *really* bad. So yeah, uh, when you get the chance, this PR's still waiting for a merge. Should take, like, 5 seconds tops. Thanks! 000
Dependabot @dependabot.bsky.social · 19/10/2023I'm not here to judge, but, you remember that big Log4j thing a while back? It was like, in the news and stuff. Aaanyway, not trying to get on your case but 2.21.0 just came out and maybe it's time to finally update that. I went ahead and closed the 2.20.0 PR for you. I'm ready whenever you are. 110
Dependabot @dependabot.bsky.social · 19/10/2023Hey, uhh... listen, I know you're busy, but look. There's a *lot* of open pull requests. Are you even working on this project anymore? Hello? Anyone? 022