Security todo
Add .github/dependabot.yml covering npm and github-actions ecosystems with weekly intervals, and enable Dependabot security updates. Without this, vulnerable or malicious dependency updates may persist until manually discovered.
Context
- Severity: High
- Category: dependency_supply_chain_review
- Confidence: Observed
- Threat: registry_supply_chain
Evidence
No .github/dependabot.yml found; 20+ runtime and dev dependencies with no automated update coverage
Security todo
Add .github/dependabot.yml covering npm and github-actions ecosystems with weekly intervals, and enable Dependabot security updates. Without this, vulnerable or malicious dependency updates may persist until manually discovered.
Context
Evidence
No .github/dependabot.yml found; 20+ runtime and dev dependencies with no automated update coverage