github-script VS dependabot-core

Compare github-script vs dependabot-core and see what are their differences.

github-script

Write workflows scripting the GitHub API in JavaScript (by actions)
SurveyJS - Open-Source JSON Form Builder to Create Dynamic Forms Right in Your App
With SurveyJS form UI libraries, you can build and style forms in a fully-integrated drag & drop form builder, render them in your JS app, and store form submission data in any backend, inc. PHP, ASP.NET Core, and Node.js.
surveyjs.io
featured
InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
github-script dependabot-core
11 30
3,942 3,879
1.6% 1.5%
6.4 10.0
about 1 month ago 3 days ago
TypeScript Ruby
MIT License GNU General Public License v3.0 or later
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.

github-script

Posts with mentions or reviews of github-script. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2023-05-22.
  • Github Actions - Output
    1 project | dev.to | 22 Aug 2023
    It's also possible to use output through the github-script action.
  • How to Terraform with Comments (And You Can DIY!*)
    3 projects | dev.to | 22 May 2023
    I wrote a custom script to parse PR comments as input commands to interface with Terraform CLI, returning the output as bot comments. Each step of the workflow relies on GitHub Actions, including actions/github-script to interact with GitHub's API (while brushing up on my JavaScript!).
  • actions-rs Github Actions need more maintainers!!! OR to be replaced
    7 projects | /r/rust | 21 Nov 2022
    You can generate what to annotate with a few lines of shell and then use gihub-script
  • GitHub Actions by Example
    13 projects | news.ycombinator.com | 24 Jan 2022
    Nice idea, worth mentioning other features:

    * Reusable workflows (note: matrix strategy doesn't work here): https://docs.github.com/en/actions/using-workflows/reusing-w...

    * Composite actions: https://docs.github.com/en/actions/creating-actions/creating...

    * Script as action: https://github.com/actions/github-script

    * Using GitHub Packages and artifacts: https://docs.github.com/en/actions/publishing-packages/about...

    * Using docker-compose-like services that run alongside of the container: https://docs.github.com/en/actions/using-containerized-servi...

    And many, many more :)

  • Automating Data Analytics Environments
    7 projects | dev.to | 7 Dec 2021
    actions/github-script@v5
  • Automatically cross-publish posts from my blog to dev.to
    2 projects | dev.to | 7 Dec 2021
    This workflow makes use of the awesome github-script that makes working with API's a breeze!
  • Paste of screenshots on GitHub isn't working with Chrome
    1 project | /r/xfce | 8 Sep 2021
    GitHub support hasn't been helpful so far. If you use Chrome on Linux, type xfce4-screenshooter or flameshot and grab a screenshot. Then navigate to any issue or PR, for example, https://github.com/actions/github-script/issues/187 and in the comment box at the bottom, type Ctrl-V. Either you'll see your image get uploaded or you won't. You don't need to save nor submit the comment.
  • Build GitHub Actions with a Docker Container
    2 projects | dev.to | 16 Feb 2021
    Note at the end of the bash, and we are leveraging a curl command to talk directly to the GitHub API. This curl command is meant for simplicity. All of this could have been done using the octokit.rest.js library or better github-script.
  • Automate your PR reviews with GitHub Action scripting in JavaScript
    3 projects | dev.to | 14 Feb 2021
    In this post, I am going to focus on the API and actions/github-script. This action makes it easy to quickly write a script in your workflow that uses the GitHub API and includes the workflow run context.
  • My First Github Workflow
    3 projects | dev.to | 6 Sep 2020
    My new github action follows a simple workflow: Whenever a user opens a pull request to the repository with the configured workflow, a comment is made on the PR with a greeting to the user and another comment with the statistics about the repository and PR are posted. Used the github-scripts (https://github.com/actions/github-script) action to get the API and context to write my own script in the workflow. It was a very fun exercise for me. Thankyou Dev Team for this cool contest!

dependabot-core

Posts with mentions or reviews of dependabot-core. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2024-04-12.
  • Why I recommend Renovate over any other dependency update tools
    6 projects | news.ycombinator.com | 12 Apr 2024
    Oh yes, https://github.com/dependabot/dependabot-core/issues/3253. I wouldn't go so far as saying it was locked because it was too uncivil, mostly just because "additional commentary wasn't adding value" ;)

    Your read on the situation is spot on, and no, it doesn't look like it's been "fixed" (mostly because "fixing it would re-introduce the same potential vulnerability).

  • Storybook 8
    5 projects | news.ycombinator.com | 13 Mar 2024
    Storybook is great and all, but these days nearly every Dependabot alert I get is about a sub-dependency of Storybook. Since Dependabot doesn't currently allow you to ignore dev dependencies and only check production dependencies [0], this makes Storybook a Big Noise Generator and every time I dismiss another alert from it, I can't help but wonder if there's a better option out there.

    [0] https://github.com/dependabot/dependabot-core/issues/2521

  • Keeping dependencies in your GitHub projects up-to-date with Dependabot
    5 projects | dev.to | 6 Jan 2024
    P.S. While this being a powerful and handy tool itself, it is only a part of Dependabot’s capabilities. If you are interested, you’ll find more about them in the GitHub docs.
  • How to Manage Helm Chart Dependency Versions?
    2 projects | /r/helm | 4 Aug 2023
    Hello! I'm using Helm in K8s and curious if there is a solution that could keep tabs on the deployed chart dependency versions and either alert us when something is out of date or when a new release is available. Does this exist? I was thinking something like Dependabot or Renovate, but neither seems to be able to manage this.
  • Dependabot vs RenovateBot
    2 projects | /r/golang | 27 Jun 2023
    - https://github.com/dependabot/dependabot-core
  • Introducing Bld: A New Pure Java Build System
    14 projects | /r/java | 12 Apr 2023
    An important point is that this kind of metadata often needs to be accessible from outside the build system itself. You need that for example in order to integration with renovate-bot or github's dependabot, to check your dependencies against CVEs, to build SBOMs and various other additional tasks that are not part of the build itself, but related to the build's metadata. This is all functionality I don't want to reimplement, I want to use what's already out there. And for that the build system needs to have some minimum amount of compatibility with existing standard metadata files like pom.xml or build.gradle
  • OpenAI, MinIO, And Why You Should Always Use docker-cli-scan To Keep Your Supply chAIn Clean
    4 projects | /r/GreyNoiseIntelligence | 24 Mar 2023
    To avoid any potential data breaches, it is recommended that users upgrade to a patched version of MinIO (RELEASE.2023-03-20T20-16-18Z) and integrate security tooling such as docker-cli-scan or use Github’s built-in monitoring for supply chain vulnerabilities, which already contains a record referencing this vulnerability.
  • OCI Helm chat repo with common apps
    4 projects | /r/kubernetes | 2 Nov 2022
    I recognize that it does not handle chart updates, but it's might still ease the burden of applying minor releases easily etc. For the chart versions themselves, unfortunately dependabot does not support this and will not, but something like renovatebot does. Could be worth looking into as a dual approach
  • Private profiles are now generally available on GitHub
    5 projects | news.ycombinator.com | 29 Sep 2022
    Disclosure: Renovate author

    Renovate is indeed AGPL, but if you're just running it as a CLI, do you think there's anything to "watch out for"? It does not make any project you run it against AGPL, that's for sure.

    Also you should be aware that dependabot-core, which dependabot-gitlab wraps, is not technically Open Source at all: https://github.com/dependabot/dependabot-core/blob/main/LICE...

  • We use Dependabot to secure GitHub
    10 projects | news.ycombinator.com | 25 May 2022
    Waiting for Yarn v2/v3 support in Dependabot has been a saga.

    https://github.com/dependabot/dependabot-core/issues/1297

What are some alternatives?

When comparing github-script and dependabot-core you can also consider the following projects:

devhub - TweetDeck for GitHub - Filter Issues, Activities & Notifications - Web, Mobile & Desktop with 99% code sharing between them

renovate - Universal dependency automation tool.

checkout - Action for checking out a repo

gradle-versions-plugin - Gradle plugin to discover dependency updates

take-action - This is an action to assign yourself to an issue for a repo you are not a contributor to.

fetch-metadata - Extract information about the dependencies being updated by a Dependabot-generated PR.

gh-action-terminal

dockerfile-samples - Dockerfile samples to make your life easier

toolkit - The GitHub ToolKit for developing GitHub Actions.

licensed - A Ruby gem to cache and verify the licenses of dependencies

setup-msys2 - GitHub Action to setup MSYS2

chaskiq - A full featured Live Chat, Support & Marketing platform, alternative to Intercom, Drift, Crisp, etc from cience.com