dependabot / dependabot/dependabot-core
Org wide Dependabot dashboard
- Dominant language
- Ruby
- Stars
- 5.8k
- Forks
- 1.5k
- Avg merge
- 2d 18h
- Merged PRs (30d)
- 149
Description
Is there an easy way for the security team in an organization to look at all dependabot results in one place?
From a vulnerability management perspective, it would be helpful to have a list of all open critical issues across the org, as opposed to going through each repo.
In the absence of such a feature, does anyone have a workaround? Has anyone found a way to import all Dependabot findings into a vuln mgmt platform such as Defect Dojo?
Contributor guide
Research direction
Start by reviewing the issue discussion and clarifying whether the goal is an organization-wide Dependabot view, export into a vulnerability-management platform, or a documented workaround. Define the supported data scope, organization access requirements, and what a complete dashboard or import workflow must show; the issue names no files, tests, or entry points.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100