Re: Did you see dependabot?

2019-11-12 Thread Martijn Dashorst
t; > > The dependabot looks interesting, cli has more possibilities than a pure > > button on GUI. > > >> does anyone enabled it > > I am all the ear how it can be enabled. > > > > On Fri, Oct 18, 2019 at 3:32 PM Enrico Olivelli > > wrote: >

Re: Did you see dependabot?

2019-10-29 Thread Tibor Digana
I have received dependabot right now and merged. https://github.com/Tibor17/surefire-tcp-connector/pull/1 Of course, my code is written just for fun and no legal issues are my problem. On Tue, Oct 29, 2019 at 7:49 PM Paul Hammant wrote: > Here's an interesting co-incidence. A chg I donated to

Re: Did you see dependabot?

2019-10-29 Thread Paul Hammant
Here's an interesting co-incidence. A chg I donated to Google's Cloud bits and pieces - https://github.com/GoogleCloudPlatform/google-cloud-datastore/pull/205/files *required and received* a CLA. @elharo just marked it as not needed, which is quite correct as this lib has been succeeded by

Re: Did you see dependabot?

2019-10-29 Thread Paul Hammant
I think you agree that the thesis has no bearing on the actions that Dependabot recommends. Worked Dependabot example https://github.com/jbehave/jbehave-tutorial/pull/19/files (I consumed this one for the JBehave team). ^ That was not copyrightable. It is not *original expression*, if it was and

Re: Did you see dependabot?

2019-10-29 Thread Martijn Dashorst
The conclusion of the paper itself is 3 pages (no paragraphs, so it might be written by an AI ;-). - Dutch (and international) copyright law don't require a copyright holder to be human - so the work itself needs to be evaluated, two criteria that factor into this; requirement of reflecting an

Re: Did you see dependabot?

2019-10-29 Thread Paul Hammant
Summary ?

Re: Did you see dependabot?

2019-10-29 Thread Martijn Dashorst
On Sat, Oct 19, 2019 at 8:51 PM Enrico Olivelli wrote: > > I see value in it. > But from a legal point of viewthere is no human who sends the PR, so in > theory we cannot accept such patches, can we? I'm not a lawyer, nor a scientist, but this paper sounds like a compelling read on this

Re: Did you see dependabot?

2019-10-19 Thread Paul Hammant
abled it > > I am all the ear how it can be enabled. > > > > On Fri, Oct 18, 2019 at 3:32 PM Enrico Olivelli > > wrote: > > > > > Hey guys, > > > Did you see dependabot on our repos? > > > > > > Like this automatic PR > > > &

Re: Did you see dependabot?

2019-10-19 Thread Enrico Olivelli
on GUI. > >> does anyone enabled it > I am all the ear how it can be enabled. > > On Fri, Oct 18, 2019 at 3:32 PM Enrico Olivelli > wrote: > > > Hey guys, > > Did you see dependabot on our repos? > > > > Like this automatic PR > > > > &g

Re: Did you see dependabot?

2019-10-19 Thread Tibor Digana
The dependabot looks interesting, cli has more possibilities than a pure button on GUI. >> does anyone enabled it I am all the ear how it can be enabled. On Fri, Oct 18, 2019 at 3:32 PM Enrico Olivelli wrote: > Hey guys, > Did you see dependabot on our repos? > > Like

Did you see dependabot?

2019-10-18 Thread Enrico Olivelli
Hey guys, Did you see dependabot on our repos? Like this automatic PR https://github.com/apache/maven-plugins/pull/147#pullrequestreview-303889692 I feel this is very useful, but... does anyone enabled it? Do we have to set a policy, this suggestions are security related fixes, we could give