Resolves: Add security and versioning dependency alerts
-
add
dependabot.ymlwhich automatically enables native Dependabot's dependency versioning scanner and dependency update PRs bot by declaring dependency ecosystems and sources in the project. For dependency security vulnerabilities scanner and vulnerable dependency update PRs bot, enable "Dependabot alerts" and "Dependabot security updates" -
should you decide that certain people on your team should take care of the PRs that Dependabot creates, use the two attributes
assigneesandreviewersto automatically set personnel respectively.
Resolves #943
Hi @aleks-ivanov, are you currently working on this item?
/AzurePipelines run
Azure Pipelines successfully started running 1 pipeline(s).
/AzurePipelines run
Azure Pipelines successfully started running 1 pipeline(s).