Skip to content

Conversation

@dependabot-preview
Copy link
Contributor

Dependabot Preview will be shut down on August 3rd, 2021. In order to keep getting Dependabot updates, please merge this PR and migrate to GitHub-native Dependabot before then.

Dependabot has been fully integrated into GitHub, so you no longer have to install and manage a separate app. This pull request updates your config file to the new syntax. When merged, we'll swap out dependabot-preview (me) for a new dependabot app, and you'll be all set!

With this change, you'll now use the Dependabot page in GitHub, rather than the Dependabot dashboard, to monitor your version updates, and you'll configure Dependabot through the new config file rather than a UI.

Your account is using config variables to access private registries. Relevant registries have been included in the new config file but additional steps may be necessary to complete the setup.
Ensure that each secret below has been configured in the organization Dependabot secrets or the repository Dependabot secrets by an admin.

  • PYTHON_INDEX_WORKIVAEAST_JFROG_IO_WORKIVAEAST_API_PYPI_PYPI_PROD_USERNAME
  • PYTHON_INDEX_WORKIVAEAST_JFROG_IO_WORKIVAEAST_API_PYPI_PYPI_PROD_PASSWORD

If an included registry is not required by this repository you can remove it from the config file.

If you've got any questions or feedback for us, please let us know by creating an issue in the dependabot/dependabot-core repository.

Learn more about migrating to GitHub-native Dependabot

Please note that regular @dependabot commands do not work on this pull request.

@dependabot-preview dependabot-preview bot added the dependencies Pull requests that update a dependency file label Apr 29, 2021
@aviary-wf
Copy link

Security Insights

(1) Vulnerable direct dependencies were detected
  • 1 vulns in pyyaml < 5.4 via requirements.txt
  • Action Items


    Questions or Comments? Reach out on Slack: #support-infosec.

    @dependabot-preview
    Copy link
    Contributor Author

    As a reminder, Dependabot Preview will be shut down on August 3rd, 2021. You can merge this pull request to migrate to GitHub-native Dependabot. You can read the docs to learn more about what's changing, as well as find out how to get support if you need help migrating.

    Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

    Labels

    dependencies Pull requests that update a dependency file Merge Requirements Unmet

    Projects

    None yet

    Development

    Successfully merging this pull request may close these issues.

    4 participants