Skip to content

[Security todo] Add Dependabot configuration for npm and GitHub Actions #338

Description

@superagent-security

Security todo

Add .github/dependabot.yml covering npm and github-actions ecosystems with weekly intervals, and enable Dependabot security updates. Without this, vulnerable or malicious dependency updates may persist until manually discovered.

Context

  • Severity: High
  • Category: dependency_supply_chain_review
  • Confidence: Observed
  • Threat: registry_supply_chain

Evidence

No .github/dependabot.yml found; 20+ runtime and dev dependencies with no automated update coverage

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions