Skip to content

A curated list of awesome Dependabot (and related software supply chain) resources.

License

Notifications You must be signed in to change notification settings

advanced-security/awesome-dependabot

Repository files navigation

awesome-dependabot Awesome

A curated list of Dependabot (and related software supply chain) resources.

Dependabot Tools

  • cli - A tool for testing and debugging Dependabot update jobs.
  • fetch-metadata - Extract information about the dependencies being updated by a Dependabot-generated PR.

Dependency Export

SBOM

Actions

  • package-policy - A GitHub action to enforce that only approved packages are used within a project by providing an allow or prohibit list of packages.
  • dependabot-actions-workflow - Example workflow for updating Dependabot pull requests
  • dependabot-kev-action - Action to detect if any open Dependabot alerts are in the CISA Known Exploited Vulnerabilities (KEV) Catalog of CVEs and fail the workflow.
  • policy-as-code - GitHub Advanced Security Policy as Code Action that supports Alerts and License compliance.
  • fetch-metadata - Extract information about the dependencies being updated by a Dependabot-generated PR.

Advisory Database

Contribute

Contributions welcome! Read the contribution guidelines first.

About

A curated list of awesome Dependabot (and related software supply chain) resources.

Topics

Resources

License

Code of conduct

Security policy

Stars

Watchers

Forks