[Pulp-dev] pulpproject.org security issues

David Davis daviddavis at redhat.com
Fri Sep 20 12:08:58 UTC 2019


I noticed this morning that Dependabot opened 3 PRs against pulpproject.org
even though we haven't given it access to that repo[0]. It turns out that
now Github is using Dependabot to open PRs for known security issues[1]. As
these are security vulnerabilities, I'd like to merge these today unless
anyone objects.

[0] https://github.com/pulp/pulpproject.org/pulls/app%2Fdependabot
[1] https://github.com/features/security#security-update

David
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/pulp-dev/attachments/20190920/a290349d/attachment.htm>


More information about the Pulp-dev mailing list