Summary
During the Wk 2 dependency + security sweep, Dependabot alerts could not be reviewed for this repo because the Dependency graph is disabled. With it off, Dependabot cannot surface vulnerability alerts or open automated security/update PRs, so this repo is effectively excluded from the weekly sweep.
Why this is filed rather than fixed in the sweep
Enabling the Dependency graph is a repository settings/access-control change. Per policy, settings/permission changes are not made automatically during the sweep — they are flagged for a maintainer to action.
Proposed work
Notes
Surfaced during the weekly PMDS dependency + security sweep (Wk 2). No code or settings were changed by the sweep.
Summary
During the Wk 2 dependency + security sweep, Dependabot alerts could not be reviewed for this repo because the Dependency graph is disabled. With it off, Dependabot cannot surface vulnerability alerts or open automated security/update PRs, so this repo is effectively excluded from the weekly sweep.
Why this is filed rather than fixed in the sweep
Enabling the Dependency graph is a repository settings/access-control change. Per policy, settings/permission changes are not made automatically during the sweep — they are flagged for a maintainer to action.
Proposed work
Notes
Surfaced during the weekly PMDS dependency + security sweep (Wk 2). No code or settings were changed by the sweep.