rombert commented on PR #6:
URL: 
https://github.com/apache/sling-org-apache-sling-jcr-davex/pull/6#issuecomment-5241137288

   > If they are not managed by the parent pom, should they be _updated_?
   
   The Dependabot guidance applies to all dep updates IMO ( 
https://cwiki.apache.org/confluence/spaces/SLING/pages/210079609/Dependabot ), 
and this would be a case of 
   
   "updating the versions of dependencies to be the oldest compatible version 
that does not have known security vulnerabilities ".
   
   If we have a reason to update, we do it. But we don't generally push the 
latest update for dependencies. Exception are runtime dependencies, e.g. Sling 
Starter.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to