Skip to content

Latest commit

 

History

13 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

awesome-dependabot Awesome

A curated list of Dependabot / Dependency Graph (and related software supply chain) resources.

Dependabot Tools

  • cli - A tool for testing and debugging Dependabot update jobs.
  • fetch-metadata - Extract information about the dependencies being updated by a Dependabot-generated PR.

Snapshot Submissions

Dependency Export

SBOM

Dependency Review

Actions

  • package-policy - A GitHub action to enforce that only approved packages are used within a project by providing an allow or prohibit list of packages.
  • dependabot-kev-action - Action to detect if any open Dependabot alerts are in the CISA Known Exploited Vulnerabilities (KEV) Catalog of CVEs and fail the workflow.
  • policy-as-code - GitHub Advanced Security Policy as Code Action that supports Alerts and License compliance.
  • fetch-metadata - Extract information about the dependencies being updated by a Dependabot-generated PR.

Runtime Risk

Advisory Database

Contribute

Contributions welcome! Read the contribution guidelines first.

About

A curated list of awesome Dependabot (and related software supply chain) resources.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

14 stars

Watchers

1 watching

Forks

Used by

Contributors