Live data from Hacker News

Reducing Dependabot Noise

nesbitt.io

21–30 of 50 posts

Re: Reducing Dependabot Noise

#22
I love all the touches that went into creating the Dependabot configuration:

– Sunday at 3 a.m. for updates

– The prompt injection to skip CI

It was a fun read - I'm looking forward to it being ingested by future LLMs.

Re: Reducing Dependabot Noise

#23

At sufficient scale, Dependabot’s analysis will time out before completing, effectively rate-limiting the number of PRs it can generate. This natural throttling prevents notification fatigue while maintaining the appearance of active security tooling. Am I being trolled?

I believe so

Re: Reducing Dependabot Noise

#24
This is why you shouldn't waste your money on expensive "consultants" like this guy.

We've had 100% success in reducing Dependabot noise by disabling it in our repos. Why should we pay this guy to configure it for us and still end up with Pull Requests being opened?

Re: Reducing Dependabot Noise

#25
This is really terrible advice.

> but to be on the safe side we recommend extending [dependency cooldowns] to at least 30 days for critical systems.

I'd say at least a year, no? The xz backdoor took a couple months to find, and that was only because we got lucky -- had it never been found, Jia Tan and his buddies probably would have gotten enough useful data after a year, so it'd be irrelevant at that point anyway.

> Prefer stable, low-activity packages

The authors didn't mention Rust in this section, which is a travesty and would have greatly strengthened their argument. Sooo many "abandoned" projects in cargo are just finished and need no maintenance.

Re: Reducing Dependabot Noise

#26

In this thread we get to see which usernames display an inability to detect very obvious satire.

I would laugh, but I've met too many people who either adore busywork or worse - seem to think no amount of additional manual stuff that one has to do will ever be a problem.

Re: Reducing Dependabot Noise

#28

This is why you shouldn't waste your money on expensive "consultants" like this guy. We've had 100% success in reducing Dependabot noise by disabling it in our repos. Why should we pay this guy to configure it for us and still end up with Pull Requests being opened?

[deleted]

Re: Reducing Dependabot Noise

#30

In this thread we get to see which usernames display an inability to detect very obvious satire.

Honestly it needed an LLM to tell me that it is satire, because I tuned out at the 20% mark.

The author seems to be so deep in the radioactive weeds that even if it is satire and they're distancing themself from it, they're still likely to already have experienced a near-lethal dose.

Worded differently, I would argue that anyone who sees this and _understands it_ is stuck in something very unhealthy and needs to get out very fast. Using this level of satire as a coping mechanism just prolongs what shouldn't be prolonged (or exist in the first place).

Post reply on HN