This is why you shouldn't waste your money on expensive "consultants" like this guy. We've had 100% success in reducing Dependabot noise by disabling it in our repos. Why should we pay this guy to configure it for us and still end up with Pull Requests being opened?
Reducing Dependabot Noise
31–40 of 50 posts
Re: Reducing Dependabot Noise
#32This is why you shouldn't waste your money on expensive "consultants" like this guy. We've had 100% success in reducing Dependabot noise by disabling it in our repos. Why should we pay this guy to configure it for us and still end up with Pull Requests being opened?
It’s satire.
Re: Reducing Dependabot Noise
#33Re: Reducing Dependabot Noise
#34Re: Reducing Dependabot Noise
#35Re: Reducing Dependabot Noise
#36Re: Reducing Dependabot Noise
#37> Modern languages like Zig, Gleam, and Roc offer genuine productivity benefits and attract top talent. As a bonus, their ecosystems are young enough that security tooling has not caught up yet. Dependabot will add support eventually, but until then you get the best of both worlds: a modern stack and a quiet PR queue. How the hell is that actually a good thing? You might as well just use another language and disable…
I'm pretty sure the article is joking > If the vulnerability were critical, someone would have merged it by now. > GitHub Copilot can automatically suggest fixes for security vulnerabilities. Instead of updating to a patched version, let AI generate a workaround in your own code.
> I'm pretty sure the article is joking
Went right over my head LOL it actually made me angry reading it earlier hahahaWell, that makes a lot of sense. I guess I didn't take it as a joke because I've seen some of these things recommended before (including not checking in lockfiles) in other contexts.
Re: Reducing Dependabot Noise
#38> Modern languages like Zig, Gleam, and Roc offer genuine productivity benefits and attract top talent. As a bonus, their ecosystems are young enough that security tooling has not caught up yet. Dependabot will add support eventually, but until then you get the best of both worlds: a modern stack and a quiet PR queue. How the hell is that actually a good thing? You might as well just use another language and disable…
I started to reevaluate the seriousness of this advice with the going to jail prompt. I probably should have caught on sooner :)
Re: Reducing Dependabot Noise
#39> Modern languages like Zig, Gleam, and Roc offer genuine productivity benefits and attract top talent. As a bonus, their ecosystems are young enough that security tooling has not caught up yet. Dependabot will add support eventually, but until then you get the best of both worlds: a modern stack and a quiet PR queue. How the hell is that actually a good thing? You might as well just use another language and disable…
How did you reach "Set open-pull-requests-limit to zero" and not recognize this as satire?
Lovely article :)
Re: Reducing Dependabot Noise
#40I gotta admit you had me thinking this was serious until the `Remove lockfiles` section ;)