1

we are thinking of using Renovate on Gitlab and havn't found anything on updating critical vulnerabilities dependencies only. We saw that it does distinguish between mayor and minor for example.

I found something in the Docs that it's possible on Github but nothing mentioned on Gitlab.

If there's no direct solution I'd also be interested with a "hacky" workaround.

Thank you

gerrel93
  • 89
  • 6
  • how to recognize an udpate with critical vulnerabilites ? You could have a packageRule with type you want: https://docs.renovatebot.com/configuration-options/#matchupdatetypes – Alexandre Gombert Oct 24 '22 at 09:16

0 Answers0