github / github/roadmap

Dependabot now supports alerting on artifacts and non-default branches [GA]

Aperta
#1,265 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Enterprise Free GHES 3.23 GitHub Advanced Security (GHAS) Paused Team
Lingua principale
Nessun dato sulla lingua
Stelle
8.9k
Fork
1.8k
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

### Value Prop
Dependabot can now generate security alerts for artifacts—such as containers, packages, and executables—as well as dependencies on non-default branches. By uploading a software bill of materials (SBOM) to GitHub's snapshot service and flagging it as alert-worthy, teams gain continuous vulnerability monitoring for every released artifact and long-running branch, not just the default branch. This closes a critical blind spot where production services and shipped products could be silently exposed to newly discovered vulnerabilities in pinned dependency versions.

### Expected Outcome
Non-default branch alerting is the most highly requested Dependabot feature in customer feedback. With this release, customers can detect zero-day vulnerabilities in any released artifact or long-lived branch—ensuring that the software they ship and operate stays protected even after the repository has moved on. We expect this to significantly reduce unpatched exposure windows, strengthen end-to-end supply chain security, and reinforce GitHub as the trusted platform for securing the entire software delivery pipeline.

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.