georgetown-cset / funder-finder

Retrieve GitHub repo funding information
Apache License 2.0
7 stars 3 forks source link

Why Not Pin the Dependencies in Requirements.txt? #33

Closed jspeed-meyers closed 1 year ago

jspeed-meyers commented 1 year ago

Mainly curious.

Pinning these could help with reproducibility across machines.

I'm glad to pin them with a PR. And as long as dependabot is activated (it it right now?), then we would get updates.

jspeed-meyers commented 1 year ago

cc @jmelot

jmelot commented 1 year ago

I don't think I have a super compelling reason for not doing this. I'm all for it! I've just enabled dependabot security alerts as well.