dependabot-core
Feedbin
Our great sponsors
dependabot-core | Feedbin | |
---|---|---|
30 | 36 | |
3,839 | 3,386 | |
1.6% | 0.9% | |
10.0 | 9.0 | |
5 days ago | 2 days ago | |
Ruby | Ruby | |
GNU General Public License v3.0 or later | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
dependabot-core
-
Why I recommend Renovate over any other dependency update tools
Oh yes, https://github.com/dependabot/dependabot-core/issues/3253. I wouldn't go so far as saying it was locked because it was too uncivil, mostly just because "additional commentary wasn't adding value" ;)
Your read on the situation is spot on, and no, it doesn't look like it's been "fixed" (mostly because "fixing it would re-introduce the same potential vulnerability).
-
Storybook 8
Storybook is great and all, but these days nearly every Dependabot alert I get is about a sub-dependency of Storybook. Since Dependabot doesn't currently allow you to ignore dev dependencies and only check production dependencies [0], this makes Storybook a Big Noise Generator and every time I dismiss another alert from it, I can't help but wonder if there's a better option out there.
[0] https://github.com/dependabot/dependabot-core/issues/2521
-
Keeping dependencies in your GitHub projects up-to-date with Dependabot
P.S. While this being a powerful and handy tool itself, it is only a part of Dependabot’s capabilities. If you are interested, you’ll find more about them in the GitHub docs.
-
How to Manage Helm Chart Dependency Versions?
Hello! I'm using Helm in K8s and curious if there is a solution that could keep tabs on the deployed chart dependency versions and either alert us when something is out of date or when a new release is available. Does this exist? I was thinking something like Dependabot or Renovate, but neither seems to be able to manage this.
-
Dependabot vs RenovateBot
- https://github.com/dependabot/dependabot-core
-
Introducing Bld: A New Pure Java Build System
An important point is that this kind of metadata often needs to be accessible from outside the build system itself. You need that for example in order to integration with renovate-bot or github's dependabot, to check your dependencies against CVEs, to build SBOMs and various other additional tasks that are not part of the build itself, but related to the build's metadata. This is all functionality I don't want to reimplement, I want to use what's already out there. And for that the build system needs to have some minimum amount of compatibility with existing standard metadata files like pom.xml or build.gradle
-
OpenAI, MinIO, And Why You Should Always Use docker-cli-scan To Keep Your Supply chAIn Clean
To avoid any potential data breaches, it is recommended that users upgrade to a patched version of MinIO (RELEASE.2023-03-20T20-16-18Z) and integrate security tooling such as docker-cli-scan or use Github’s built-in monitoring for supply chain vulnerabilities, which already contains a record referencing this vulnerability.
-
OCI Helm chat repo with common apps
I recognize that it does not handle chart updates, but it's might still ease the burden of applying minor releases easily etc. For the chart versions themselves, unfortunately dependabot does not support this and will not, but something like renovatebot does. Could be worth looking into as a dual approach
-
Private profiles are now generally available on GitHub
Disclosure: Renovate author
Renovate is indeed AGPL, but if you're just running it as a CLI, do you think there's anything to "watch out for"? It does not make any project you run it against AGPL, that's for sure.
Also you should be aware that dependabot-core, which dependabot-gitlab wraps, is not technically Open Source at all: https://github.com/dependabot/dependabot-core/blob/main/LICE...
-
We use Dependabot to secure GitHub
Waiting for Yarn v2/v3 support in Dependabot has been a saga.
Feedbin
-
Show HN: ADHD STASH. A curated collection of ADHD friendly products and services
It would work the same for me, if only because I'd redirect the email to my RSS reader (via Feedbin[0] or Kill the Newsletter[1] or similar)! I suspect most people who care about RSS would do the same, but the Webflow docs[2] show it being pretty straightforward to set up, and (imo) it's an easy backup hedge against all your comms getting stuck in spam filters. Plus, it just feels more ADHD-friendly to me to reduce ping noise as much as possible.
- Killed by Google
- At its peak, Google Reader had 30M users but no executive support
-
Reddit API Changes, Subreddit Blackout, and How It Affects You
I use Feedbin to read them. Because of their open nature nobody can tell the sole developer there “people can only read feeds using our app, and you can go pound sand”.
-
Web browser-based RSS reader
Comes to my mind one that I bumped into a while ago: Feedbin, although I haven't tried it. It's web based and it costs $5/month but it has a 30 day trial period. It works also through third party apps on Android and iOS (well, the latter seems to have a dedicated one by themselves).
-
Pick of the Day - 4/23/23 (Sunday)
There’s a RSS feed which you can use with something like feedbin.com
-
Mac Power Users 686: Consuming Content in 2023
Links and Show Notes:More Power Users: Ad-free episodes with regular bonus segmentsSubmit FeedbackApple Releases iOS and iPadOS 16.4 with New Emoji, Notifications for Web Apps on the Home Screen, Voice Isolation for Cellular Calls, New Shortcuts Actions, and More - MacStoriesReadwiseKindle ScribeAmazon.com: How to Calm Your Mind by Chris BaileyMac Power Users #550: The World of RSS - Relay FMReadwise ReaderReeder 5FeedbinSubscribe to Email Newsletters in FeedbinGoodLinksThe Disney Bundle: Stream Disney+, Hulu, and ESPN+YouTube TVJustWatch AppCuriosity StreamYouTube PremiumCGP Grey - YouTubeHands-On With Apple's New Classical Music App - MacRumorsOvercastLibbyThree Thoughts Spurred by a Random iOS 5 Screenshot – 512 PixelsStephen Hackett (@[email protected]) - eworld.socialMacSparky (@[email protected]) - MastodonSofa: Downtime Organizer
-
Google Reader shut down announced ten years ago today
I can recommend https://feedbin.com/ as a great replacement. It's $50 a year, but in return you get a service that is rock solid with an owner who is luckily very good in >> not << implementing features: no feature creep, no breaking changes, no BS.
-
Why does no one talk about RSS readers?
I enjoy using Feedbin, as it's not only my own newsfeed for blogs, but it also supports Twitter too. The interface has a clean, thoughtful design which is really important for me.
-
Weekly Self-Hosted Poll: Which RSS feed reader/aggregator are you using?
I no longer self host it, but there is a community contributed Docker Compose stack for Feedbin.
What are some alternatives?
renovate - Universal dependency automation tool.
NewsBlur - NewsBlur is a personal news reader that brings people together to talk about the world. A new sound of an old instrument.
gradle-versions-plugin - Gradle plugin to discover dependency updates
Miniflux - Minimalist and opinionated feed reader
fetch-metadata - Extract information about the dependencies being updated by a Dependabot-generated PR.
FreshRSS - A free, self-hostable news aggregator…
dockerfile-samples - Dockerfile samples to make your life easier
Winds - A Beautiful Open Source RSS & Podcast App Powered by Getstream.io
licensed - A Ruby gem to cache and verify the licenses of dependencies
FeedHQ - FeedHQ is a web-based feed reader
chaskiq - A full featured Live Chat, Support & Marketing platform, alternative to Intercom, Drift, Crisp, etc from cience.com
CommaFeed - Google Reader inspired self-hosted RSS reader.