Skip to content

Conversation

magnusbaeck
Copy link
Member

Applicable Issues

Fixes #117

Description of the Change

Weekly Dependabot updates are unnecessary and will only result in lots of go.mod churn. If something security-sensitive pops up we'll be notified right away. Monthly dependency updates are enough.

Alternate Designs

None.

Possible Drawbacks

We'll pick up important upgrades that lack security implications.

Sign-off

Developer's Certificate of Origin 1.1

By making a contribution to this project, I certify that:

(a) The contribution was created in whole or in part by me and I have the right to submit it under the open source license indicated in the file; or

(b) The contribution is based upon previous work that, to the best of my knowledge, is covered under an appropriate open source license and I have the right under that license to submit that work with modifications, whether created in whole or in part by me, under the same open source license (unless I am permitted to submit under a different license), as indicated in the file; or

(c) The contribution was provided directly to me by some other person who certified (a), (b) or (c) and I have not modified it.

(d) I understand and agree that this project and the contribution are public and that a record of the contribution (including all personal information I submit with it, including my sign-off) is maintained indefinitely and may be redistributed consistent with this project or the open source license(s) involved.

Signed-off-by: Magnus Bäck <[email protected]>

Weekly Dependabot updates are unnecessary and will only result
in lots of go.mod churn. If something security-sensitive pops
up we'll be notified right away.
@magnusbaeck magnusbaeck requested a review from a team as a code owner July 17, 2025 12:56
@magnusbaeck magnusbaeck requested review from t-persson and removed request for a team July 17, 2025 12:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Reduce frequency of Dependabot updates
1 participant