GitHub can now alert of supply-chain bugs in new dependencies

This page summarizes the projects mentioned and recommended in the original post on /r/programming

Our great sponsors
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • WorkOS - The modern identity platform for B2B SaaS
  • SaaSHub - Software Alternatives and Reviews
  • dependabot-core

    🤖 Dependabot's core logic for creating update PR's.

  • I believe the intent is to have a github action upload the dependency manifest during a build, so that it can be evaluated by dependabot. Similarly to sarif reports by static analysis tools. See the current proposal and github issue.

  • gradle-versions-plugin

    Gradle plugin to discover dependency updates

  • In the meantime you can use the gradle-versions-plugin or one of its extensions. I wrote it a decade ago and naively hoped they would have offered something built-in and better by now. Maybe they finally will if the above moved forward.

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts