Investigate/implement Dependabot #5843

Closed
opened 2026-01-31 00:23:12 +00:00 by claunia · 2 comments
Owner

Originally created by @miniksa on GitHub (Jan 9, 2020).

It's very interesting seeing Windows Terminal will have some of it's source code coming from Chromium. I'd also suggest configuring dependabot to update this dependency source from the github mirror as updates to the source occur.

Originally posted by @WSLUser in https://github.com/microsoft/terminal/pull/4144#issuecomment-572697227

Originally created by @miniksa on GitHub (Jan 9, 2020). It's very interesting seeing Windows Terminal will have some of it's source code coming from Chromium. I'd also suggest configuring dependabot to update this dependency source from the github mirror as updates to the source occur. _Originally posted by @WSLUser in https://github.com/microsoft/terminal/pull/4144#issuecomment-572697227_
claunia added the Help WantedIssue-TaskNeeds-Tag-FixProduct-MetaArea-CodeHealth labels 2026-01-31 00:23:12 +00:00
Author
Owner

@WSLUser commented on GitHub (Jan 9, 2020):

FYI, Github should of already provided the service for other dependencies unless it was already disabled. https://help.github.com/en/github/managing-security-vulnerabilities/configuring-automated-security-updates. If not, there are other existing mechanisms that can be utilized. Openssh portable (from which win32 openssh forks from) auto pulls from the mainstream openssh project for instance.

@WSLUser commented on GitHub (Jan 9, 2020): FYI, Github should of already provided the service for other dependencies unless it was already disabled. https://help.github.com/en/github/managing-security-vulnerabilities/configuring-automated-security-updates. If not, there are other existing mechanisms that can be utilized. Openssh portable (from which win32 openssh forks from) auto pulls from the mainstream openssh project for instance.
Author
Owner

@DHowett commented on GitHub (Jun 29, 2022):

It looks like dependabot implemented itself!

@DHowett commented on GitHub (Jun 29, 2022): It looks like dependabot implemented itself!
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/terminal#5843