Skip to content

Do you recommend pinning organizational presets? #29111

Discussion options

You must be logged in to vote

I don't think most people would need to do this, because the "noise" it creates (a PR/commit in every repo each time there's a change to the central preset) likely isn't worth it for the "safety" it provides. Also if you set it to automatically merge the upgrades you probably break yourself anyway.

On the other hand, the more pinned your dependencies are (and this is in theory a dependency too), the more reproducible your software is, so I wouldn't call it a bad idea.

This could perhaps be done with a custom regex manager, although "first class" support with its own manager would be nice too.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by sheldonhull
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants