Advertisement · 728 × 90
#
Hashtag
#dependabot
Advertisement · 728 × 90

For dev tools and other projects where Denial of Service is not a concerning vulnerability its a wise idea to filter those out so that the noise of DoS vulnerabilities doesn't drown out the rest.

Here's a filter for GitHub's #Dependabot alerts: gist.github.com/voxpelli/d68...

1 0 1 0

@github.com all dependabot PRs since yesterday are stuck waiting for approval to run workflow.
If that change is intentional, there has to be a way to create an exception for @dependabot.bsky.social

0 0 0 0
Post image

Don’t let your supply chain be a black box. 📦

#Gradle + #GitHub = Automated dependency tracking and faster vulnerability response.

Secure your builds today. 🛡️⚡️

blog.gradle.org/avoid-supply-chain-disas...

#Dependabot

0 0 0 0
Post image

Manual audits can't keep up with dynamic Gradle builds. ⚙️

Automate your security with GitHub’s Dependency Graph & Gradle Build Scan. Trace every CVE to its source. 🔍

blog.gradle.org/avoid-supply-chain-disas...

#Gradle #GitHub #Dependabot #CVE

2 0 0 0
Preview
Avoiding the Next Supply Chain Disaster with GitHub and Gradle Supply chain security is a big deal, and it’s dangerously easy to ignore. For Android or JVM developers, the sheer scale of the ecosystem is our greatest strength, and our greatest risk.

Declared dependencies are just the tip of the iceberg. 🧊

Use the #Gradle + #Github integration to surface hidden transitive vulnerabilities and automate your response. 🛡️

Read more: blog.gradle.org/avoid-supply-chain-disas...

#Dependabot

0 0 0 0
Preview
Go lib maintainer: GitHub's Dependabot is a 'noise machine' : When a one-line fix triggers thousands of PRs, something's off

⚠️ Go lib maintainer: GitHub's Dependabot is a 'noise machine'

#Dependabot #vulnerability #github #opensource #cybersecurity

4 1 1 0
Preview
How To Configure Dependabot To Automatically Upgrade OpenJDK In Docker Images A common issue you may want to automate as part of your CI/CD pipelines is the upgrading of your JDK in Docker images. Similar to how you…

If you've ever wondered how to automate the upgrading of your JDK in Docker images, you might want to checkout my latest article.

medium.com/devops-by-na...

#build
#cicd
#dependabot
#devops
#devsecops
#git
#github
#jdk #java #openjdk #temurin #eclipse
#softwaredevelopment #softwareengineering

3 1 0 0
Preview
How To Set Up GitHub Code Quality GitHub recently released a new feature called Code Quality. It brings static analysis, intelligent automation and actionable feedback…

If you'd like to find out how to set up GitHub Code Quality, you can check out my latest article on Medium.

#cicd
#codequality
#devops
#devsecops
#git
#github
#ghas
#codeql
#dependabot
#scm #vcs #versioncontrol
#sast
#devlearning #softwaredevelopment #softwareengineering

medium.com/devops-by-na...

0 0 0 0

#Dependabot alerted me to a high-severity defect in a transient dependency (the dependency is from Stripe!). The same day a user reported a defect in the system that's apparently been there for quite some time. Both are now fixed in production.

So that's how my #NYE is going.

1 0 0 0
Original post on mastodon.social

If dependabot had been able to FF merge the changes that could be FF merged that would have cut down the number of dependabot commits by half.

And it would seriously reduced the visual clutter of main branch by more than the reduction of the number of commits.

#dependabot #gitCommitClutter […]

0 0 0 0
Preview
Scripts to automatically commit dependabot PRs. Scripts to automatically commit dependabot PRs. GitHub Gist: instantly share code, notes, and snippets.

Just had to commit plenty of dependabot PRs (update of the checkout action).

Here are my scripts that made it a bit easier:
gist.github.com/floitsch/4d3...

#github #dependabot

1 0 1 0
Preview
Update uv-build requirement from <0.9.0,>=0.8.11 to >=0.8.11,<0.10.0 in the python group by dependabot[bot] · Pull Request #17 · honzajavorek/p3news Updates the requirements on uv-build to permit the latest version. Updates uv-build to 0.9.2 Release notes Sourced from uv-build's releases. 0.9.2 Release Notes Released on 2025-10-10. Python...

Dependabot umí i tohle? To je cool. https://github.com/honzajavorek/p3news/pull/17/files

#dependabot #uv #buildsystem #requires #python

0 1 1 0

Looks like GitHub is tweaking Dependabot PR comment commands. Good to know ahead of Oct 2025 so I can update my muscle memory. Always a small re-learning curve with these changes! 😅 #Dependabot #GitHub

1 0 0 0
Preview
How GitHub Became The De Facto Standard For Open Source and Enterprise Software Development In the past couple of decades, software development has undergone a dramatic transformation. What was once the domain of small, niche…

Check out out my latest article on how GitHub became the de facto standard platform for software development.

#cicd #devops #devsecops #git #github #ghas #codeql #dependabot #scm #vcs #versioncontrol #opensource #devlearning #softwaredevelopment #softwareengineering

medium.com/devops-by-na...

4 0 0 0
A screenshot of my notifications, all from GitHub's dependabot.

A screenshot of my notifications, all from GitHub's dependabot.

Not even my friends and family talk to me this much 😢 #GitHub #dependabot

1 0 0 0

For those who moved their projects from #GitHub to @Codeberg

What do you use instead of #dependabot?
If you are not selfhosting runners, what do you use?

#developer #codeberg #runners

2 0 0 0
This could have destroyed the entire web (the next one probably will)
This could have destroyed the entire web (the next one probably will) YouTube video by Theo - t3․gg

IDK about you but I have to start paying more attention to changelogs. Also reducing dependencies by literally copying source code from small (open source) packages is a game changer. #npm #github #hacked #dependabot www.youtube.com/watch?v=jo4L...

3 0 1 0
Preview
Dependabot support for vcpkg - C++ Team Blog We are excited to announce that GitHub’s Dependabot now brings automated dependency updates to C++ projects using vcpkg. This support is available for projects using vcpkg manifest files, empowering…

Dependabot support for vcpkg | by James Magee.

buff.ly/4TG12In

#cpp #vcpkg #dependabot #devsecops

0 0 0 0
Preview
Enable Dependabot everywhere Enable Dependabot everywhere. GitHub Gist: instantly share code, notes, and snippets.

Enable #Dependabot on each @GitHub 's #PHP project:

gist.github.com/Vitexus/436fdc710bb5c9c1...

#Security #Development

0 0 0 0
Preview
The new Dependabot NuGet updater: 65% faster with native .NET - .NET Blog Discover the new Dependabot NuGet updater that improves performance, accuracy, and developer experience by leveraging native .NET tooling.

The new Dependabot NuGet updater: 65% faster with native .NET.

buff.ly/1zE8G6h

#nuget #dotnet #performance #dependabot

1 0 0 0

I so hope this fixes some of the recent bugs I've been seeing. It has looked from the outside like the #dependabot team was struggling.

0 0 1 0
Preview
The new Dependabot NuGet updater: 65% faster with native .NET - .NET Blog Discover the new Dependabot NuGet updater that improves performance, accuracy, and developer experience by leveraging native .NET tooling.

Nice updates for how #dependabot uses #nuget with #dotnet

devblogs.microsoft.com/dotnet/the-new-dependabo...

2 1 1 0
Original post on devblogs.microsoft.com

The new Dependabot NuGet updater: 65% faster with native .NET Discover the new Dependabot NuGet updater that improves performance, accuracy, and developer experience by leveraging native .NET tooli...

#.NET #NuGet #Dependabot #msbuild #Package […]

[Original post on devblogs.microsoft.com]

0 0 0 0
Original post on chaos.social

Fnally, there is the option to run Github dependabot on a cron job base <3
(released in April, I haven't seen it before)

github.blog/changelog/2025-04-22-dep... […]

1 0 0 0
Original post on hachyderm.io

Does #Microsoft even care about #Dependabot at all any more? The #dotnet support has multiple open bugs causing valid configurations (that is, ones that worked at the beginning of the year) not to produce results, for months now. For a commercially supported product, that feels like a sad joke […]

1 2 2 0

Why isn't there a #docker compose #github action?

#github gives you `services`, but if you use them, you likely have a docker-compose.yml, and then you're duplicating your dependencies.

Plus, #dependabot doesn't know how to update `services` images, so your dependencies get stale.

1 0 0 0

holy shit dependabot can now run on depot runners 🤯

flip one setting and your dependency updates become near instant

you're welcome

docs in 🧵

#github #dependabot #cicd

1 0 1 0
Original post on accioly.social

1/5 Heya Fed, Hint of the day for the devs out there: I was heavily reliant on Dependabot to keep my project's software versions up to date (you are keeping your dependencies up to date, right?).

Some colleagues who are deeper into OSS told me to try Renovate, but I mostly dismissed it as just […]

0 0 0 0
Original post on accioly.social

1/5 Heya Fed, Hint of the day for the devs out there: I was heavily reliant on Dependabot to keep my project's software versions up to date (you are keeping your dependencies up to date, right?).

Some colleagues who are deeper into OSS told me to try Renovate, but I mostly dismissed it as just […]

0 0 0 0