Dependabot's repositories
dependabot-core
🤖 Dependabot's update PR creation logic. Feedback: https://github.com/orgs/community/discussions/categories/code-security
dependabot-script
A simple script that demonstrates how to use Dependabot Core
elixir-security-advisories
Old database of Elixir security advisories before the GitHub Security Advisory DB supported Hex / Elixir.
fetch-metadata
Extract information about the dependencies being updated by a Dependabot-generated PR.
dependabot-actions-workflow
Example workflow for updating Dependabot pull requests
gem-vulnerability-analysis
Jupyter notebook for a blog post on gem vulnerabilities and version updates.
gomodules-extracted
This code was originally used in dependabot-core, but has since been removed. See Readme for details.
dummy-packages
Dummy packages for testing Dependabot
prometheus-aggregator-ruby
A Ruby client for https://github.com/peterbourgon/prometheus-aggregator
smoke-tests
A collection of manifest files for various package managers and is used to perform end-to-end tests for Dependabot.
php-dummy-pkg-a
A dummy PHP package for testing Dependabot.
updater-action
Runs Dependabot Updates via GitHub Actions. This fork exists because the Action used to live in the Dependabot org prior to GA. So beta customers may still depend on its original location.
php-dummy-pkg-b
A dummy PHP package for testing Dependabot.