Show HN: Dependabot – Automated Dependency Update PRs for Ruby, JS, Python and PHP
dependabot.com
dependabot.com
OT but Kudos on linking the "Trusted by" icons (though it's only gov.uk that points to something that is actually using it). These Trusted by Microsoft, Slack, Techcrunch, etc icons are ubiquitous on every site and project but nobody ever links to it for details/proof. I wish more people would do this instead of just making a huge collage of brand icons.
And yes - totally agree!
1. Their pre-sales support was great and they went out of their way to accommodate our requirements. 2. You can get ongoing support from them by @ing the bot in a PR (and they reply inline!). 3. It drip-feeds you updates (5 a day), so a really old project is still manageable. 4. The PR message contains links to release notes, changelog, and actual commits, for the library in question. This is such a time save (and reveals how many OSS projects don't have decent changelogs).
Edit: ooh, I see its oss and this search indicates Pipfile support is likely: https://github.com/dependabot/dependabot-core/search?utf8=%E...
The biggest difference to Gemnasium is that we’ll creat the update PRs for you automatically. The biggest difference to Greenkeeper is that we handle lockfiles out of the box and give you compatibility scores for each update. We love both services, though!