Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Increase Dependabot schedule frequency to weekly to catch CVEs faster

オープン 初心者向け
#559 コメント 1 件 リアクション 1 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
2/5
見積もり時間
1〜3時間
初心者へのやさしさ
68/100
issue の種類
機能追加
明瞭さ
おおむね明確
活発さ
活発
技術スタック
go
領域
ci-cd

調査の方向性

.github/dependabot.yml から始め、gomod のスケジュールと提案で対象となっているその他のエコシステムを確認します。open-pull-requests-limit を 3 に維持したまま、該当する間隔を weekly に変更し、その後、結果の設定が要求されたスケジュールと上限に一致することを確認します。

索引モデルが issue の本文から書いたものです。

説明

Description

Our Dependabot gomod ecosystem is currently set to run on a monthly schedule.

Waiting up to 30 days for automated dependency updates is a bit too long, especially when critical security vulnerabilities are discovered. Dependabot randomly picks 3 from pool of many and make PRs. So the dependecy resolution become slow. For example, a recent govulncheck scan flagged 10 active vulnerabilities in our codebase that Dependabot hasn't picked up yet due to the monthly schedule and pull req limits:

  • 2 vulnerabilities in golang.org/x/crypto (GO-2026-6355, GO-2026-6354) - Fixed in v0.56.0
  • 8 vulnerabilities in the Go Standard Library (GO-2026-6218, GO-2026-6090, GO-2026-6089, GO-2026-5972, GO-2026-5856, GO-2026-5039, GO-2026-5037, GO-2026-5026) - Fixed in Go 1.26.6
Proposal

We should update .github/dependabot.yml to change the interval for gomod (and potentially the others) from monthly to weekly. We should keep the open-pull-requests-limit: 3 exactly as it is to make sure no spam.

It is a open discussion.
@yada @Harsh4902

主要言語
Go
スター
52
フォーク
67
平均マージ
3日 23時間
マージ済み PR(30日)
23

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

microcks/microcks-cli のほかの issue

microcks/microcks-cli の issue をすべて見る

似ている issue

Go の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。