Replies: 2 comments
-
@MarcinNowak-codes we rather not, as we cover not all type of UI or Infrastructure tests 👍 . |
Beta Was this translation helpful? Give feedback.
-
I would say it is better not to, and I would like to add one more point over the valid one raised by @commjoen. Regarding security, a new corrupted bugfix version could be somehow published to a central repository, which would make it automatically integrated into the main branch of the project. Happened in the past multiple times in the node ecosystem, being it intentional by the maintainer or coming from someone else:
Even if tools are like dependabot automate all the grinding in dependencies upgrade, a human eye is needed to have a safe upgrade. 🙂 |
Beta Was this translation helpful? Give feedback.
-
Should Dependabot's pull request be automatically merge when pipeline is green?
Beta Was this translation helpful? Give feedback.
All reactions