Dependabot alerts paused for malware advisories
github.blog
github.blog
I now recommend Renovate to clients which is also free, but a lot smarter.
Unless it opens a full-fledged PR with the fixes and a good description of WHY, I don't want it.
To be clear, I'm not arguing to not update vulnerable dependencies, though often enough my project doesn't actually use the vulnerable part of said dependency, effectively making the whole exercise somewhat pointless, akin to virtue signaling for dependencies. Sounds dumb, right?
For work projects, I appreciate it. For my open source experiments, not so much.
If there was a way to let the bot do everything from beginning to end, merging and possibly breaking everything without manual intervention, that could be exciting! (Probably in a bad way? Milage will surely vary!)
Realistically, no, I don't think so.
You're making a choice between updating everything as soon as possible, or batching everything until it's actually needed. Both valid approaches, but I prefer the first. It saves you when one day you discover that you really need to do some critical update... but now it also depends on updates to foo, bar and baz, and changes to your code because some API got deprecated and you need to figure out how they impacts your external interface. I'd rather deal with 100 trivial/pointless updates trickling in daily instead of one of those situations.
Anyway, this kind of attack would also work with Renovate but you could create a good company-wide config to prevent this.