Hi,

a few weeks ago, I noticed, that a lot of mails are generated by
@dependabot on the TomEE repositories.

It contains a lot of false positives (i.e. in the examples) and often
requires additional efforts (i.e. code changes, xml adjustments) to
upgrade.

We are updating the dependencies before releases anyway (if they are
important), so I am wondering, if we should disable @dependabot for the
TomEE repositories?

According to INFRA, it is possible to disable via 
https://cwiki.apache.org/confluence/display/INFRA/Git+-+.asf.yaml+features#Git.asf.yamlfeatures-DependabotAlertsandUpdates

Any thoughts? ;)

Richard

Attachment: smime.p7s
Description: S/MIME cryptographic signature

Reply via email to