Its currently hard to differentiate Dependabot PRs that resolve current CVEs from those that are simply evergreening our dependencies. Review the configuration and ensure that CVE resolving PRs are clearly labelled as such so that we can prioritise reviewing and merging them.
Its currently hard to differentiate Dependabot PRs that resolve current CVEs from those that are simply evergreening our dependencies. Review the configuration and ensure that CVE resolving PRs are clearly labelled as such so that we can prioritise reviewing and merging them.