Sitelet https://web.archive.org/web/20220126222346/https://github.com/github/roadmap/issues/343
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot Security Updates (Server) - Public Beta #343

Open
github-product-roadmap opened this issue Dec 15, 2021 · 0 comments
Open

Dependabot Security Updates (Server) - Public Beta #343

github-product-roadmap opened this issue Dec 15, 2021 · 0 comments

Comments

@github-product-roadmap
Copy link
Collaborator

@github-product-roadmap github-product-roadmap commented Dec 15, 2021

Summary

Dependabot Security Updates keep projects secure by opening pull requests that update dependencies to a non-vulnerable version. This extends Dependabot Security Updates to GitHub Enterprise Server (GHES) as a public beta. This release is targeting GitHub Enterprise Server 3.4.

Intended Outcome

Most projects use open source, and vulnerabilities in open source code are common. Dependabot helps to keep your projects updated and secure.

How will it work?

Today, Dependabot Security Updates automatically create a pull request in your repository to upgrade a vulnerable dependency to the minimum possible secure version needed to avoid the vulnerability. This is an automated action corresponding to Dependabot Alerts in your repository, for repositories where Dependency Graph is enabled.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
Status: Q1 2022 – Jan-Mar
GitHub public roadmap
Q1 2022 – Jan-Mar
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
1 participant