Skip to content

advanced-security/awesome-dependabot

Repository files navigation

awesome-dependabot Awesome

A curated list of Dependabot (and related software supply chain) resources.

Dependabot Tools

  • cli - A tool for testing and debugging Dependabot update jobs.
  • fetch-metadata - Extract information about the dependencies being updated by a Dependabot-generated PR.

Dependency Export

SBOM

Actions

  • package-policy - A GitHub action to enforce that only approved packages are used within a project by providing an allow or prohibit list of packages.
  • dependabot-kev-action - Action to detect if any open Dependabot alerts are in the CISA Known Exploited Vulnerabilities (KEV) Catalog of CVEs and fail the workflow.
  • policy-as-code - GitHub Advanced Security Policy as Code Action that supports Alerts and License compliance.
  • fetch-metadata - Extract information about the dependencies being updated by a Dependabot-generated PR.

Advisory Database

Contribute

Contributions welcome! Read the contribution guidelines first.

About

A curated list of awesome Dependabot (and related software supply chain) resources.

Topics

Resources

License

Code of conduct

Security policy

Stars

Watchers

Forks

Contributors 2

  •  
  •