AI / Dependabot Interview questions
What is the "vendor" option in Dependabot configuration, and when is it needed?
vendor: true tells Dependabot that a project vendors its dependencies — meaning
dependency source code is committed directly into the repository (rather than fetched from a remote registry
at build/install time), a pattern common in some Go and Ruby projects for build reproducibility or offline
build support.
updates: - package-ecosystem: "bundler" directory: "/" vendor: true schedule: interval: "weekly"
Without this flag, Dependabot would only update the manifest/lock file reference to a new version, leaving
the actual vendored source code in the repository out of sync with what the manifest claims — setting
vendor: true tells Dependabot to also update the actual vendored files to match, keeping both in
consistent agreement rather than silently drifting apart.
More Related questions...