Live data from Hacker News

Reducing Dependabot Noise

nesbitt.io

31–40 of 50 posts

Re: Reducing Dependabot Noise

#31

This is why you shouldn't waste your money on expensive "consultants" like this guy. We've had 100% success in reducing Dependabot noise by disabling it in our repos. Why should we pay this guy to configure it for us and still end up with Pull Requests being opened?

It’s satire.

Re: Reducing Dependabot Noise

#32

This is why you shouldn't waste your money on expensive "consultants" like this guy. We've had 100% success in reducing Dependabot noise by disabling it in our repos. Why should we pay this guy to configure it for us and still end up with Pull Requests being opened?

It’s satire.

So is the comment you replied to...

Re: Reducing Dependabot Noise

#37

> Modern languages like Zig, Gleam, and Roc offer genuine productivity benefits and attract top talent. As a bonus, their ecosystems are young enough that security tooling has not caught up yet. Dependabot will add support eventually, but until then you get the best of both worlds: a modern stack and a quiet PR queue. How the hell is that actually a good thing? You might as well just use another language and disable…

I'm pretty sure the article is joking > If the vulnerability were critical, someone would have merged it by now. > GitHub Copilot can automatically suggest fixes for security vulnerabilities. Instead of updating to a patched version, let AI generate a workaround in your own code.

   > I'm pretty sure the article is joking
Went right over my head LOL it actually made me angry reading it earlier hahaha

Well, that makes a lot of sense. I guess I didn't take it as a joke because I've seen some of these things recommended before (including not checking in lockfiles) in other contexts.

Re: Reducing Dependabot Noise

#38

> Modern languages like Zig, Gleam, and Roc offer genuine productivity benefits and attract top talent. As a bonus, their ecosystems are young enough that security tooling has not caught up yet. Dependabot will add support eventually, but until then you get the best of both worlds: a modern stack and a quiet PR queue. How the hell is that actually a good thing? You might as well just use another language and disable…

I started to reevaluate the seriousness of this advice with the going to jail prompt. I probably should have caught on sooner :)

I didn't manage to get to that point of the article out of pure anger... He got me all right LOL

Re: Reducing Dependabot Noise

#39
post #11

> Modern languages like Zig, Gleam, and Roc offer genuine productivity benefits and attract top talent. As a bonus, their ecosystems are young enough that security tooling has not caught up yet. Dependabot will add support eventually, but until then you get the best of both worlds: a modern stack and a quiet PR queue. How the hell is that actually a good thing? You might as well just use another language and disable…

How did you reach "Set open-pull-requests-limit to zero" and not recognize this as satire?

You wouldn't believe how many of these things I've seen seriously recommended before. Also, I do have difficulty detecting sarcasm sometimes (even though I'm very fond of it).

Lovely article :)

Re: Reducing Dependabot Noise

#40

I gotta admit you had me thinking this was serious until the `Remove lockfiles` section ;)

I stopped there and had to read the answers to my comment to find out and revisit it. In hindsight, this is absolutely hilarious. Might be one of my new favorite pieces of software satire (because of how realistic, albeit absurd, it is).
Post reply on HN