diff --git a/_posts/2023/2023-03-28-dependabot-codebase.md b/_posts/2023/2023-03-28-dependabot-codebase.md new file mode 100644 index 0000000000000000000000000000000000000000..182c60a6948eb30087e56e44333d3e55c2a3b3ba --- /dev/null +++ b/_posts/2023/2023-03-28-dependabot-codebase.md @@ -0,0 +1,64 @@ +--- +title: "Helmholtz Codebase: Automating Dependency Updates" +title_image: clark-tibbs-oqStl2L5oxI-unsplash.jpg +date: 2023-03-28 +authors: + - hueser + - huste + - ziegner +layout: blogpost +categories: + - News +tags: + - Announcement + - GitLab + - Codebase + - Dependabot +excerpt: + We are happy to announce the general availability of + <a href="https://dependabot-gitlab.gitlab.io/dependabot/">automated dependency update management</a> + in the <a href="https://codebase.helmholtz.cloud/">Helmholtz Codebase GitLab</a>. + It provides automatic dependency updates in order to + keep your software up-to-date and secure. + +--- + +{{ page.excerpt }} + +## Why should you bother? + +Outdated dependencies with known security flaws is one of the most +frequent security issues that get exploited most often. +Enabling automated dependency updates helps you saving time +by keeping track of all dependency updates, automating +time-consuming recurring dependency update tasks, and staying +secure in your application. + +## All Information in One Place + +Beside the versions of the old and new dependency, it provides you with +information about the release notes as well as the commit history. + +## How does it work? + +The bot will automatically create Merge Requests for dependency updates: + + + +The list of supported ecosystems is given [here](https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/about-dependabot-version-updates#supported-repositories-and-ecosystems). +Among others, Python, Docker or Git submodules are supported. If you want to +use Dependabot for your software project, you can find the setup instructions +in our [documentation](https://hifis.net/doc/software/gitlab/dependabot/#configuration). + +## Comments and Suggestions + +If you have suggestions, questions, or queries, please don't hesitate to write us. + +<a href="{% link contact.md %}" + class="btn btn-outline-secondary" + title="HIFIS Helpdesk"> + Contact us! <i class="fas fa-envelope"></i></a> + +## References + +* [Documentation](https://hifis.net/doc/software/gitlab/dependabot/) diff --git a/assets/img/posts/2023-03-20-dependabot-codebase/dependabot_merge_request.png b/assets/img/posts/2023-03-20-dependabot-codebase/dependabot_merge_request.png new file mode 100644 index 0000000000000000000000000000000000000000..f619b275e16a0315096a65bb0e76f9d1d32882ff Binary files /dev/null and b/assets/img/posts/2023-03-20-dependabot-codebase/dependabot_merge_request.png differ