-
Notifications
You must be signed in to change notification settings - Fork 5
Open
Description
Summary
Enable GitHub Dependabot vulnerability alerts for the repository so known vulnerable dependencies are automatically detected and surfaced early in the Security tab.
Goals
- Detect vulnerable dependencies automatically via GitHub’s advisory database.
- Surface alerts in Security → Dependabot alerts for maintainers to triage.
- Improve baseline security posture with minimal maintenance overhead.
Non-Goals
- Automatic version update PRs (Dependabot version updates).
- Replacing other security controls (CodeQL, review, etc.).
- Establishing SLA policies for alert remediation in this ticket.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels
Type
Projects
Status
Next