Developer meetup: Dependabot for Jenkins plugin development
Details
January 24, 2020 @ 16:00 UTC | 8:00 PT | 11:00 ET. Zoom link: https://zoom.us/j/620163429 . This meetup will help Jenkins plugin maintainers and contributors.
Dependency management helps developers as they select components. Updated dependencies reduce the risk of security issues from outdated code. Dependency updates are good, but dependency management can be a chore.
Many Jenkins repositories have enabled Dependabot to automate the submission of pull requests for dependency updates. Dependabot makes it easy to detect and review dependency updates.
Attend this session to learn how you can use Dependabot to simplify plugin development.
Tentative agenda:
- Oleg Nenashev - Dependabot Overview - Why, What, When
- Mark Waite, Oleg Nenashev - Using Dependabot in Jenkins? (for Java, JavaScript and Docker)
- Oleg Nenashev - What's next for us? Dependabot at scale, and what do we miss?
- Q&A
Related materials:
- Discussion thread: http://bit.ly/30wrlPg
