GitHub
Code quality
Security & compliance
Dependabot security updates disabled
Part of the Repository protection posture check · fix arrives as a guide
What it is
Dependabot security updates are turned off, so no pull request is opened when a dependency has a known vulnerability with a fix available.
Why it matters
You are relying on someone reading the advisory feed. The window between a CVE being published and your patching it is the window in which exploitation is easiest, because the vulnerability is now public.
How to fix it
Enable Dependabot alerts and security updates in the repository settings so a patched version arrives as a pull request you can review and merge.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.