You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Amend the following paragraph to state that each maintainer must configure each repo to watch security alerts. Otherwise we believe no notification will be sent, even if security alerts are enabled for the repo.
Description
The maintainers guidelines need to be updated to state the need to act on Dependabot updates & alerts. The most relevant document to update is probably this: https://github.com/eiffel-community/community/blob/master/GOVERNANCE.md#maintainers
This was discussed on a TC meeting in Nov 2022
Dependabot PRs
Also, announce the new Dependabot policy on the Eiffel Community maillist
Repositories that are de facto inactive and don’t update their dependencies should be considered for demotion to dormant.
Motivation
We need clear directives towards the maintainers of the Eiffel Community repos on how to handle Dependabot alerts
Exemplification
Info easily found from this point: https://github.com/eiffel-community/community/blob/master/GOVERNANCE.md#maintainers
Benefits
Faster and more controlled updates of vulnerabilities
Possible Drawbacks
Additional effort needed from maintainers, but given the current uncertainty on how to handle the dependabot issues/PRs the gain is probably higher
The text was updated successfully, but these errors were encountered: