Skip to content

Conversation

@joncinque
Copy link
Contributor

Problem

Dependabot updates all versions of packages, which is less flexible for end users. Libraries are more useful when dependencies are relaxed.

Summary of changes

Change the open pull request number to 0 to only enable security updates, as documented at
Dependabot's documentation

#### Problem

Dependabot updates all versions of packages, which is less flexible for
end users. Libraries are more useful when dependencies are relaxed.

#### Summary of changes

Change the open pull request number to 0 to only enable security
updates, as documented at
[Dependabot's documentation](https://docs.github.com/en/code-security/dependabot/dependabot-security-updates/configuring-dependabot-security-updates#overriding-the-default-behavior-with-a-configuration-file)
@joncinque joncinque merged commit 828307c into solana-program:main Sep 30, 2025
29 checks passed
@joncinque joncinque deleted the dependabot-security branch September 30, 2025 10:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants