hackforla / peopledepot

A project to setup a datastore for people and projects at HackforLA. The link below takes you to the code documentation
https://hackforla.github.io/peopledepot/
GNU General Public License v2.0
5 stars 24 forks source link

Set up security update checks in CI #296

Open fyliu opened 3 weeks ago

fyliu commented 3 weeks ago

Overview

We need to set up something like PyUp once we're deployed so that we're up-to-date for security updates.

Details

PyUP is a tool that updates all your project's Python dependency files through Pull Requests on GitHub/GitLab. It's repo is currently inactive and the project was converted to a product called Safety, this issue will explore alternatives including but not limited to:

Action Items

Resources/Instructions

fyliu commented 3 weeks ago

Looks like pyup hasn't been updated in years and the project was converted to a product called Safety. Here's a list of alternatives to consider. Or

ExperimentsInHonesty commented 6 days ago

@fyliu I rewrote the issue a little bit. Please review and if you are good with the way it is now, please add the ready for product label back on.