PRs from Fake Dependabot

This page summarizes the projects mentioned and recommended in the original post on /r/webdev

InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
  • This is a pretty serious flaw in GitHub. Especially on mobile, it would be very easy to be tricked into thinking that a PR was legitimately from Dependabot. In the app, you can't notice see the URL of the profile to see if it's https://github.com/apps/dependabot. You could even review changes in the PR but maybe not notice a letter swap in a package name. Even requiring signatures isn't enough since commits on the web are signed with the exact same key Dependabot uses!

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project