milesmcc / shynet

Modern, privacy-friendly, and detailed web analytics that works without cookies or JS.
Apache License 2.0
2.87k stars 180 forks source link

Dependency Updates #314

Open StarkZarn opened 4 months ago

StarkZarn commented 4 months ago

Hi, love the project! I'm curious as to if you have a roadmap for dependency updates. I personally like dependabot and renovate, whichever is easier for a given person. Even without big feature updates, I find that dependency updates are pretty easy and important to keep things secure.

milesmcc commented 4 months ago

Hey! No current roadmap for dependency updates, but I am planning on doing a bigger Shynet revamp in the coming months.

milesmcc commented 4 months ago

There are currently no open dependabot alerts; I do try to be fairly quick about merging those when they do come up. Is there a different approach that you'd suggest?

StarkZarn commented 4 months ago

What do you have configured for dependabot? I didn't see a dependabot config file in the .github directory. I forked it just to check things and currently have 10 pull requests open from dependabot. https://github.com/StarkZarn/shynet/pulls