Remix.run Logo
mook 8 hours ago

Too bad dependabot cooldowns are brain-dead. If you set a cooldown for one week, and your dependency can't get their act together and makes a release daily, it'll start making PRs for the first (oldest) release in the series after a week even though there's nothing cool about the release cadence.

kleyd 8 hours ago | parent [-]

The cooldown is to allow vulnerabilities to be discovered. So auto update on passing tests, which should include an npm audit check.