Skip to content

[Security] Enable Dependency graph so Dependabot alerts/updates run on this repo #130

Description

@PAMulligan

Summary

During the Wk 2 dependency + security sweep, Dependabot alerts could not be reviewed for this repo because the Dependency graph is disabled. With it off, Dependabot cannot surface vulnerability alerts or open automated security/update PRs, so this repo is effectively excluded from the weekly sweep.

Why this is filed rather than fixed in the sweep

Enabling the Dependency graph is a repository settings/access-control change. Per policy, settings/permission changes are not made automatically during the sweep — they are flagged for a maintainer to action.

Proposed work

  • A maintainer enables Dependency graph under Settings → Advanced Security (or Code security & analysis).
  • Enable Dependabot alerts and Dependabot security updates.
  • Re-run the dependency sweep on this repo once alerts populate.

Notes

Surfaced during the weekly PMDS dependency + security sweep (Wk 2). No code or settings were changed by the sweep.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions