Replies: 2 comments
-
|
I am concerned about this as well. Automerge doesn't show as an option for users who have the ability to override merge status checks, so this is an oversight for pretty much every single small project. |
Beta Was this translation helpful? Give feedback.
-
|
As for me, it’s really helpful to merge dependencies with a comment. It’s useful if Dependabot keeps rebasing due to conflicts, but you’re sure that everything is fine with the update. For JS/TS projects, it’s going to be a real pain in the ass 😕 |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
I had been relying on
@dependabot mergeto help protect my projects from dependabot phishing attacks on my repository -- the logic being that if someone attempts to credibly APPEAR as dependabot opens a PR, and I fail to detect that spoofing in my review,@dependabot mergewould be a final safeguard because the attacker would not have the rights to merge.I saw that this feature is being deprecated, and the guidance is to use GitHub UX to perform the action. My concern is that using the UX would remove that final auth-based safeguard.
Does the dependabot team have any suggestions for how I might maintain that layer of safety / avoid human error in my review process?
After posting this I see there is also a feedback thread on the broader GH community page too: https://github.com/orgs/community/discussions/176097
Beta Was this translation helpful? Give feedback.
All reactions