Hi, a few weeks ago, I noticed, that a lot of mails are generated by @dependabot on the TomEE repositories.
It contains a lot of false positives (i.e. in the examples) and often requires additional efforts (i.e. code changes, xml adjustments) to upgrade. We are updating the dependencies before releases anyway (if they are important), so I am wondering, if we should disable @dependabot for the TomEE repositories? According to INFRA, it is possible to disable via https://cwiki.apache.org/confluence/display/INFRA/Git+-+.asf.yaml+features#Git.asf.yamlfeatures-DependabotAlertsandUpdates Any thoughts? ;) Richard
smime.p7s
Description: S/MIME cryptographic signature
