Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Highlight updates requiring closer review #15

Open
robertknight opened this issue Jun 7, 2022 · 0 comments
Open

Highlight updates requiring closer review #15

robertknight opened this issue Jun 7, 2022 · 0 comments

Comments

@robertknight
Copy link
Member

This morning I encountered a situation where a package update was received that had no release notes:

Diff release notes

At the time of writing, there is no tag in the package's GitHub repository that corresponds to the v5.1.0 release. The package diff looks legitimate, so I think this is a case where the maintainer simply forgot to push a tag.

It would be helpful if this tool could flag such suspicious updates and require additional confirmation before merging.

Some ideas of things to look out for:

  • Empty release notes in diff (where empty includes notes that only contain Dependabot's standard boilerplate)
  • Maintainer change (this info is present in some Dependabot PRs, but not currently highlighted in this tool's CLI output)
  • Missing GitHub release or tag for package
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant