-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Appenv projects: support tools like renovate and dependabot #56
Comments
Both renovate and dependabot only support a variety of pre-defined project package managers: While renovate supports some sort of mechanism that allows us to use custom files ( Ultimately though, both support The This is similiar to |
How to implement: Add #1 together with a versioning scheme for appenv repositories that allows for executing migrations when upgrading in between versions. |
https://pypi.org/project/appenv/#description releases gehören hierzu |
We can consider using uv with their |
Ultimately, deployments using e.g. batou, which use appenv as it's installation mechanism, save their requirements in the repository where appenv is used.
Since the requirements are locked by appenv, only the specified versions are used. Usage may run outdated and vulnerable dependency versions.
Tools like renovate and dependabot can update locked dependencies and warn if dependency requirements exclude known safe versions.
The text was updated successfully, but these errors were encountered: