Skip to content

Conversation

@PythonGermany
Copy link
Contributor

Summary

Also monitor npm dependency versions with dependabot.

Checklist

  • Tested and/or added tests to validate that the changes work as intended, if applicable.
  • (n/a) Updated documentation in README.md, if applicable.

@TwiN
Copy link
Owner

TwiN commented Dec 8, 2025

I don't know about this. NPM has too many packages with security issues lately. I would rather not update npm packages as often, at the cost of trivial frontend CVEs, than risk accidentally releasing Gatus with a malicious package because everything gets auto updated.

@PythonGermany
Copy link
Contributor Author

PythonGermany commented Dec 8, 2025

I understand. We could set the interval to weekly or monthly instead of daily or maybe even quarterly?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants