Commit 1025317
committed
Do not update dependencies when bumping versions
Yes, we do run automated tests with the new versions, but there is a
concern about supply chain security here. I'd rather explicitly rely on
our Dependabot pull requests that have a cooldown period configured to
not accidentally include an insecure update when cutting a release.1 parent f4a3e98 commit 1025317
2 files changed
Lines changed: 0 additions & 8 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
65 | 65 | | |
66 | 66 | | |
67 | 67 | | |
68 | | - | |
69 | | - | |
70 | | - | |
71 | 68 | | |
72 | 69 | | |
73 | 70 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
81 | 81 | | |
82 | 82 | | |
83 | 83 | | |
84 | | - | |
85 | | - | |
86 | | - | |
87 | | - | |
88 | | - | |
89 | 84 | | |
90 | 85 | | |
91 | 86 | | |
| |||
0 commit comments