Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Move to Snyk for security checks #3804

Open
1 of 2 tasks
pydanny opened this issue Jul 23, 2022 · 2 comments
Open
1 of 2 tasks

Move to Snyk for security checks #3804

pydanny opened this issue Jul 23, 2022 · 2 comments

Comments

@pydanny
Copy link
Member

pydanny commented Jul 23, 2022

PyUP just sent me notice that on August 1 all repos must be on paid plans.

  • Find an alternative (Snyk preferred, I'll ask them if they can assist)
  • Switch from PyUP to alternative
@pydanny pydanny changed the title PyUP going to only paid plans Move to Snyk for security checks Jul 23, 2022
@rdegges
Copy link

rdegges commented Jul 24, 2022

No problemo! Snyk is happy to sponsor cookiecutter =) Will send DM with details.

@browniebroke
Copy link
Member

browniebroke commented Dec 31, 2024

I noticed today that our template dependencies aren't being kept up to date by dependabot, presumably due to a bug in the bot and also perhaps because we use uv in the template project.

Are there been any progress on this? @rdegges I would be happy to pick this up, I think I should have enough access to this repo looks like I need to be an org admin. Does Snyk support uv as package manager?

Alternatively, I've used Renovate which seemingly support everything under the sun (including uv) and is highly customisable. Also supports auto-merging after a delay for certain types of upgrades (patch/minor, but not major), hence reducing the maintenance efforts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants