Scheduled dependency updates
Author: rosemarykuCreated Mar 31, 2025Updated Jun 2, 2025
Labelsneeds discussion
Problem Description
To minimize security vulnerabilities, enabling Dependabot, Renovate or another alternative for scheduled dependency updates would be useful.
Since the package-lock.json file is not published, there's no way to verify dependencies have the upgraded.
Potential Solution
Enable Dependabot, Renovate or another alternative for scheduled dependency updates to enhance security and outdated dependencies.
Snyk is another option that can be considered as a developer security platform to help identify vulnerabilities in dependencies.
Source: downshift-js/downshift