This repo contains some projects with outdated dependencies. Fork it to try out
Dependabot !
- In your fork, click the Settings tab
- In the left hand side navigation, click Code security and analysis
- Enable Dependabot security updates or Grouped security updates
- Dependabot will now start creating PRs for detected security vulnerabilities
- Go into the Security tab and click Dependabot in the left hand side navigation to see what Dependabot is working on
data:image/s3,"s3://crabby-images/b22d1/b22d1165b5b89504bbea628123238f0bb83e9b1d" alt="screenshot showing Dependabot working on Security Updates"
After about 5 minutes you should see some PRs open. Merge them and the Securty Alerts will close 🎉
This demo includes a dependabot.yml
which configures Version Updates, but forks don't automatically start with Dependabot enabled.
The enable Dependabot on your fork:
- Click the Insights tab
- In the left hand side navigation, click Dependency Graph
- Click on the Dependabot tab
- Click on the Enable Dependabot button
- After a moment, refresh the page and you should see Dependabot hard at work
data:image/s3,"s3://crabby-images/d70f8/d70f893e4c6f2637d6ac75d57111e76c0bd1042a" alt="screenshot showing Dependabot working on Version Updates"
After a few minutes, you should get some more PRs!