Hacker News new | ask | show | jobs
by rvanmil 2583 days ago
Did GitHub just activate this without confirmation or notification? I'm suddenly receiving PR's on my repo's from dependabot without ever activating this tool.

Edit: looks like they defaulted to enable "Automated security fixes" on the Security > Alerts tab.