You add your repo and a bot is constantly checking for insecure and/or outdated packages and sends you a pull request if you need to update.
It's free for open source projects at https://pyup.io
You add your repo and a bot is constantly checking for insecure and/or outdated packages and sends you a pull request if you need to update.
It's free for open source projects at https://pyup.io
I was initially concerned that constant PR's for dependencies would be too noisy for our team but it turned out that it's configurable enough and gracefully handles us ignoring or closing PR's that we evaluate and decide to wait on.
It's a great service that all python developers should be using. (I say that because I want as many pyup users as possible so it never goes away)
A quick suggestion, consider adding a full sample configuration along with your config docs: https://pyup.io/docs/configuration/
It's a lot easier to see how it all sits together with a sample.
CircleCI has a great example: https://circleci.com/docs/1.0/config-sample/
This it how it looks like: https://github.com/pydanny/cookiecutter-django/pull/1065