[Question] enable dependabot and start updating lib dependencies especially when there are security issues #3000
Labels
dependencies
Pull requests that update a dependency file
good first issue
Good for newcomers
question
Further information is requested
task
Question
I tested in my fork and dependabot reports about 70 security issues (CVEs) due to outdated dependencies in Hertzbeat. Most are NPM based but some are Java issues (commons-net, kafka-client, mysql).
The text was updated successfully, but these errors were encountered: