GitHub Enterprise Server now supports the "one pipeline" framework for dependency graph generation [GA]
- 主要语言
- 没有语言数据
- 星标
- 8.9k
- 派生
- 1.8k
- PR 合并指标
- 30 天内没有已合并 PR
描述
### Value Prop
GitHub Enterprise Server now supports the "one pipeline" framework for dependency graph generation, bringing years of dependency graph platform improvements to GHES customers. This includes transitive dependency resolution, dev dependency labelling, broader ecosystem support, and private registry credential handling — capabilities previously available only on GitHub.com. With this update, GHES customers get a more accurate, comprehensive view of their software supply chain without needing to change their workflows.
### Expected Outcome
GHES customers gain parity with GitHub.com's modern dependency graph pipeline, enabling richer dependency insights and stronger supply chain security posture out of the box. By consolidating on the "one pipeline" framework and deprecating legacy generation methods, we reduce platform complexity and ensure all customers benefit from ongoing dependency graph improvements as they ship. This drives deeper adoption of GitHub's supply chain security features across the enterprise segment.
贡献指南
调研方向
此路线图 issue 描述了 GitHub Enterprise Server 依赖关系图所需的结果,但没有指出任何文件、测试或代码入口点。首先确定现有的 GHES 依赖关系图生成路径,以及 legacy 和“one pipeline”实现。完成的标准是 GHES 使用现代 pipeline,并具备所列出的依赖关系解析、标记、生态系统和凭据处理能力。
由索引模型根据 Issue 内容生成。
评估
- 领域
- security
- Issue 类型
- 功能
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 冷清
- 描述清晰度
- 需要澄清
- 新手友好度
- 25/100