home.social

#dependabot — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #dependabot, aggregated by home.social.

  1. RE: mastodon.social/@hugovk/116399

    Starting with v8.0.0, Astral switched setup-uv to immutable releases with no floating v8 tags. This is good for security.

    But unfortunately #Dependabot and #Renovate couldn't upgrade from v7 to v8.0.0, and need a manual bump to get back on track. This is not so good for security.

    I posted about this on the three social networks, someone tagged @www.jvt.me and soon after Renovate now supports this! 🎉

    Here's his writeup into the world of #GitHubActions tags:
    jvt.me/posts/2026/04/24/github

  2. RE: mastodon.social/@hugovk/116399

    Starting with v8.0.0, Astral switched setup-uv to immutable releases with no floating v8 tags. This is good for security.

    But unfortunately #Dependabot and #Renovate couldn't upgrade from v7 to v8.0.0, and need a manual bump to get back on track. This is not so good for security.

    I posted about this on the three social networks, someone tagged @www.jvt.me and soon after Renovate now supports this! 🎉

    Here's his writeup into the world of #GitHubActions tags:
    jvt.me/posts/2026/04/24/github

  3. RE: mastodon.social/@hugovk/116399

    Starting with v8.0.0, Astral switched setup-uv to immutable releases with no floating v8 tags. This is good for security.

    But unfortunately #Dependabot and #Renovate couldn't upgrade from v7 to v8.0.0, and need a manual bump to get back on track. This is not so good for security.

    I posted about this on the three social networks, someone tagged @www.jvt.me and soon after Renovate now supports this! 🎉

    Here's his writeup into the world of #GitHubActions tags:
    jvt.me/posts/2026/04/24/github

  4. RE: mastodon.social/@hugovk/116399

    Starting with v8.0.0, Astral switched setup-uv to immutable releases with no floating v8 tags. This is good for security.

    But unfortunately #Dependabot and #Renovate couldn't upgrade from v7 to v8.0.0, and need a manual bump to get back on track. This is not so good for security.

    I posted about this on the three social networks, someone tagged @www.jvt.me and soon after Renovate now supports this! 🎉

    Here's his writeup into the world of #GitHubActions tags:
    jvt.me/posts/2026/04/24/github

  5. RE: mastodon.social/@hugovk/116399

    Starting with v8.0.0, Astral switched setup-uv to immutable releases with no floating v8 tags. This is good for security.

    But unfortunately #Dependabot and #Renovate couldn't upgrade from v7 to v8.0.0, and need a manual bump to get back on track. This is not so good for security.

    I posted about this on the three social networks, someone tagged @www.jvt.me and soon after Renovate now supports this! 🎉

    Here's his writeup into the world of #GitHubActions tags:
    jvt.me/posts/2026/04/24/github

  6. After my recent playing around with #Copilot, I thought I'd take a look at my Github billing report to see how much I'd used. I have, this month, used US$5.80 worth of Copilot ... and US$870 of actions.

    Most of those computrons got burned when #Dependabot pushed branches and then when it created pull requests so that it could whine at me about point releases of stuff like #CrossPlatformActions (github.com/cross-platform-acti).

    1/n

  7. After my recent playing around with , I thought I'd take a look at my Github billing report to see how much I'd used. I have, this month, used US$5.80 worth of Copilot ... and US$870 of actions.

    Most of those computrons got burned when pushed branches and then when it created pull requests so that it could whine at me about point releases of stuff like (github.com/cross-platform-acti).

    1/n

  8. After my recent playing around with #Copilot, I thought I'd take a look at my Github billing report to see how much I'd used. I have, this month, used US$5.80 worth of Copilot ... and US$870 of actions.

    Most of those computrons got burned when #Dependabot pushed branches and then when it created pull requests so that it could whine at me about point releases of stuff like #CrossPlatformActions (github.com/cross-platform-acti).

    1/n

  9. After my recent playing around with #Copilot, I thought I'd take a look at my Github billing report to see how much I'd used. I have, this month, used US$5.80 worth of Copilot ... and US$870 of actions.

    Most of those computrons got burned when #Dependabot pushed branches and then when it created pull requests so that it could whine at me about point releases of stuff like #CrossPlatformActions (github.com/cross-platform-acti).

    1/n

  10. After my recent playing around with #Copilot, I thought I'd take a look at my Github billing report to see how much I'd used. I have, this month, used US$5.80 worth of Copilot ... and US$870 of actions.

    Most of those computrons got burned when #Dependabot pushed branches and then when it created pull requests so that it could whine at me about point releases of stuff like #CrossPlatformActions (github.com/cross-platform-acti).

    1/n

  11. 🚨 TeamPCP hijacks Bitwarden CLI in supply chain attack, abusing GitHub Dependabot to deploy Shai-Hulud malware and steal developer secrets, poison AI coding tools.

    Read: hackread.com/teampcp-bitwarden

  12. 🚨 TeamPCP hijacks Bitwarden CLI in supply chain attack, abusing GitHub Dependabot to deploy Shai-Hulud malware and steal developer secrets, poison AI coding tools.

    Read: hackread.com/teampcp-bitwarden

    #CyberSecurity #TeamPCP #Malware #Bitwarden #GitHub #Dependabot

  13. 🚨 TeamPCP hijacks Bitwarden CLI in supply chain attack, abusing GitHub Dependabot to deploy Shai-Hulud malware and steal developer secrets, poison AI coding tools.

    Read: hackread.com/teampcp-bitwarden

    #CyberSecurity #TeamPCP #Malware #Bitwarden #GitHub #Dependabot

  14. 🚨 TeamPCP hijacks Bitwarden CLI in supply chain attack, abusing GitHub Dependabot to deploy Shai-Hulud malware and steal developer secrets, poison AI coding tools.

    Read: hackread.com/teampcp-bitwarden

    #CyberSecurity #TeamPCP #Malware #Bitwarden #GitHub #Dependabot

  15. 🚨 TeamPCP hijacks Bitwarden CLI in supply chain attack, abusing GitHub Dependabot to deploy Shai-Hulud malware and steal developer secrets, poison AI coding tools.

    Read: hackread.com/teampcp-bitwarden

    #CyberSecurity #TeamPCP #Malware #Bitwarden #GitHub #Dependabot

  16. Do you use astral-sh/setup-uv@v7 in #GitHubActions?

    And it's not hash-pinned?

    And you use #Dependabot or #Renovate?

    The setup-uv project has switched to only Vx.y.z tags, no more Vx or Vx.y.

    But Dependabot and Renovate won't upgrade from Vx to Vx.y.z, so you'll need to manually update to [email protected] to keep up with future updates.

    "To increase security even more we will stop publishing minor tags. You won't be able to use v8 or v8.0 any longer."

    github.com/astral-sh/setup-uv/
    #Python #uv

  17. Do you use astral-sh/setup-uv@v7 in #GitHubActions?

    And it's not hash-pinned?

    And you use #Dependabot or #Renovate?

    The setup-uv project has switched to only Vx.y.z tags, no more Vx or Vx.y.

    But Dependabot and Renovate won't upgrade from Vx to Vx.y.z, so you'll need to manually update to [email protected] to keep up with future updates.

    "To increase security even more we will stop publishing minor tags. You won't be able to use v8 or v8.0 any longer."

    github.com/astral-sh/setup-uv/
    #Python #uv

  18. Do you use astral-sh/setup-uv@v7 in #GitHubActions?

    And it's not hash-pinned?

    And you use #Dependabot or #Renovate?

    The setup-uv project has switched to only Vx.y.z tags, no more Vx or Vx.y.

    But Dependabot and Renovate won't upgrade from Vx to Vx.y.z, so you'll need to manually update to [email protected] to keep up with future updates.

    "To increase security even more we will stop publishing minor tags. You won't be able to use v8 or v8.0 any longer."

    github.com/astral-sh/setup-uv/
    #Python #uv

  19. Do you use astral-sh/setup-uv@v7 in #GitHubActions?

    And it's not hash-pinned?

    And you use #Dependabot or #Renovate?

    The setup-uv project has switched to only Vx.y.z tags, no more Vx or Vx.y.

    But Dependabot and Renovate won't upgrade from Vx to Vx.y.z, so you'll need to manually update to [email protected] to keep up with future updates.

    "To increase security even more we will stop publishing minor tags. You won't be able to use v8 or v8.0 any longer."

    github.com/astral-sh/setup-uv/
    #Python #uv

  20. Do you use astral-sh/setup-uv@v7 in #GitHubActions?

    And it's not hash-pinned?

    And you use #Dependabot or #Renovate?

    The setup-uv project has switched to only Vx.y.z tags, no more Vx or Vx.y.

    But Dependabot and Renovate won't upgrade from Vx to Vx.y.z, so you'll need to manually update to [email protected] to keep up with future updates.

    "To increase security even more we will stop publishing minor tags. You won't be able to use v8 or v8.0 any longer."

    github.com/astral-sh/setup-uv/
    #Python #uv

  21. is #js the next #java applets, some may remember, there were so many viruses and hacks has been happening with #applets around 2000s at the end they drop the applets totally.

    Now having #dependabot or #snyk is like just bringing a new security hole strangely opposite the intention.

    Probably better to not upgrade if all versions are secure and stay there forever 😃

    youtube.com/watch?v=o7NYXvYohYk

  22. is #js the next #java applets, some may remember, there were so many viruses and hacks has been happening with #applets around 2000s at the end they drop the applets totally.

    Now having #dependabot or #snyk is like just bringing a new security hole strangely opposite the intention.

    Probably better to not upgrade if all versions are secure and stay there forever 😃

    youtube.com/watch?v=o7NYXvYohYk

  23. is #js the next #java applets, some may remember, there were so many viruses and hacks has been happening with #applets around 2000s at the end they drop the applets totally.

    Now having #dependabot or #snyk is like just bringing a new security hole strangely opposite the intention.

    Probably better to not upgrade if all versions are secure and stay there forever 😃

    youtube.com/watch?v=o7NYXvYohYk

  24. is #js the next #java applets, some may remember, there were so many viruses and hacks has been happening with #applets around 2000s at the end they drop the applets totally.

    Now having #dependabot or #snyk is like just bringing a new security hole strangely opposite the intention.

    Probably better to not upgrade if all versions are secure and stay there forever 😃

    youtube.com/watch?v=o7NYXvYohYk

  25. is the next applets, some may remember, there were so many viruses and hacks has been happening with around 2000s at the end they drop the applets totally.

    Now having or is like just bringing a new security hole strangely opposite the intention.

    Probably better to not upgrade if all versions are secure and stay there forever 😃

    youtube.com/watch?v=o7NYXvYohYk

  26. ⚠️ Go lib maintainer: GitHub's Dependabot is a 'noise machine'

    「 He argues that dependencies should be updated according to the project's development cycle, not whenever a new version of a package appears. Updating quickly also carries some risk if malicious code has been added to a package. 」

    theregister.com/2026/02/24/git

    #Dependabot #vulnerability #github #opensource #cybersecurity

  27. ⚠️ Go lib maintainer: GitHub's Dependabot is a 'noise machine'

    「 He argues that dependencies should be updated according to the project's development cycle, not whenever a new version of a package appears. Updating quickly also carries some risk if malicious code has been added to a package. 」

    theregister.com/2026/02/24/git

    #Dependabot #vulnerability #github #opensource #cybersecurity

  28. ⚠️ Go lib maintainer: GitHub's Dependabot is a 'noise machine'

    「 He argues that dependencies should be updated according to the project's development cycle, not whenever a new version of a package appears. Updating quickly also carries some risk if malicious code has been added to a package. 」

    theregister.com/2026/02/24/git

    #Dependabot #vulnerability #github #opensource #cybersecurity

  29. ⚠️ Go lib maintainer: GitHub's Dependabot is a 'noise machine'

    「 He argues that dependencies should be updated according to the project's development cycle, not whenever a new version of a package appears. Updating quickly also carries some risk if malicious code has been added to a package. 」

    theregister.com/2026/02/24/git

    #Dependabot #vulnerability #github #opensource #cybersecurity

  30. ⚠️ Go lib maintainer: GitHub's Dependabot is a 'noise machine'

    「 He argues that dependencies should be updated according to the project's development cycle, not whenever a new version of a package appears. Updating quickly also carries some risk if malicious code has been added to a package. 」

    theregister.com/2026/02/24/git

    #Dependabot #vulnerability #github #opensource #cybersecurity

  31. RE: mastodon.social/@h4ckernews/11

    I have a good story with #dependabot
    I was working with a team that depended totally in #bots #llms #ai stack. So one day checking PRs I noticed a PR that overrides the dependencies of the framework that we used to build an API( #NestJS ) Yeah it was overriding the depends of Nestjs in our repo, I mean the dependencies of the dependencies

    Why?

    They told me that dependabot warnings about it.

    I'm pretty sure the solution came from #chatgpt hahahahaahhaa

  32. RE: mastodon.social/@h4ckernews/11

    I have a good story with #dependabot
    I was working with a team that depended totally in #bots #llms #ai stack. So one day checking PRs I noticed a PR that overrides the dependencies of the framework that we used to build an API( #NestJS ) Yeah it was overriding the depends of Nestjs in our repo, I mean the dependencies of the dependencies

    Why?

    They told me that dependabot warnings about it.

    I'm pretty sure the solution came from #chatgpt hahahahaahhaa

  33. RE: mastodon.social/@h4ckernews/11

    I have a good story with #dependabot
    I was working with a team that depended totally in #bots #llms #ai stack. So one day checking PRs I noticed a PR that overrides the dependencies of the framework that we used to build an API( #NestJS ) Yeah it was overriding the depends of Nestjs in our repo, I mean the dependencies of the dependencies

    Why?

    They told me that dependabot warnings about it.

    I'm pretty sure the solution came from #chatgpt hahahahaahhaa

  34. RE: mastodon.social/@h4ckernews/11

    I have a good story with #dependabot
    I was working with a team that depended totally in #bots #llms #ai stack. So one day checking PRs I noticed a PR that overrides the dependencies of the framework that we used to build an API( #NestJS ) Yeah it was overriding the depends of Nestjs in our repo, I mean the dependencies of the dependencies

    Why?

    They told me that dependabot warnings about it.

    I'm pretty sure the solution came from #chatgpt hahahahaahhaa

  35. Wow, found a great use case for GitHub Copilot. It can help Dependabot finish update bumps that require code changes!

    #github #copilot #dependabot #update #upgrade #ai #migration #pullrequest #automation #developer #code #agents