Given that you already have Dependabot active, would you consider getting the dependencies somewhat up to date? Looks like the pull requests already exist... Thanks.
Given that you already have Dependabot active, would you consider getting the dependencies somewhat up to date? Looks like the pull requests already exist... Thanks.
Did you read through the security issues identified, familiar with the codebase enough that you can see that these issues are actually affecting the product?
Most issues Dependabot opens on repositories I'm involved in, points to issues that has no bearing on the actual code, since it's security issues that are involving passing user code to specific functions, or simply regarding APIs that are never used in the first place.
You don't have to be on the newest version of every single library, in most cases it doesn't make any sense to just upgrade for the sake of upgrade.
Create a GitHub native tools suite for LTS management of all releases of all languages/platforms, then we are talking about security.