<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=7837&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / GitHub and Dependabot]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=7837</link>
		<description><![CDATA[The most recent posts in GitHub and Dependabot.]]></description>
		<lastBuildDate>Wed, 25 Feb 2026 20:03:05 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[GitHub and Dependabot]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=62461#p62461</link>
			<description><![CDATA[<p>Hello:</p><p>Yes, you read right: <em>Dependabot</em></p><p>------<br /><strong>Go library maintainer brands GitHub&#039;s Dependabot a &#039;noise machine&#039;</strong><br />When a one-line fix triggers thousands of PRs, something&#039;s off<br />by Tim Anderson&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; Tue 24 Feb 2026 // 16:31 UTC<br />------</p><p><a href="https://www.theregister.com/2026/02/24/github_dependabot_noise_machine/?td=rt-3a" rel="nofollow">https://www.theregister.com/2026/02/24/ … /?td=rt-3a</a></p><div class="quotebox"><cite>Tim Anderson@The Register wrote:</cite><blockquote><div><p>A Go library maintainer has urged developers to turn off GitHub&#039;s Dependabot, arguing that false positives from the dependency-scanning tool &quot;reduce security by causing alert fatigue.&quot;</p></div></blockquote></div><p>Best,</p><p>A.</p>]]></description>
			<author><![CDATA[dummy@example.com (Altoid)]]></author>
			<pubDate>Wed, 25 Feb 2026 20:03:05 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=62461#p62461</guid>
		</item>
	</channel>
</rss>
