Topic
#dependabot
Loot, blog posts and adjacent themes connected to this topic. Follow the tag to keep it in your orbit.
Loot
More from this topic
Blog
Related reads
Tools & Apps
Delay Dependabot Version PRs Before Fresh Packages Hit Your Build
GitHub now delays Dependabot version update pull requests for three days by default, giving maintainers and scanners time to catch compromis…
Tools & Apps
Use GitHub Innersource Advisories before internal packages hide security fixes
GitHub Advanced Security enterprise customers can now publish private internal advisories that trigger Dependabot alerts and fixes across re…
Tools & Apps
Audit Dependabot alert exports before GitHub moves old closed alerts out of the API
GitHub will move closed Dependabot security alerts older than two years into archival storage on August 25, 2026, changing how security team…
Tools & Apps
Fix Dependabot npm registry scope before private package updates drift
GitHub changed how Dependabot handles npm registry configuration: teams can now make dependabot.yml the authoritative source for scoped npm …

