close
The Wayback Machine - https://web.archive.org/web/20211027060114/https://github.com/github/roadmap/issues/135
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot alerts for GHAE #135

Open
github-product-roadmap opened this issue Dec 2, 2020 · 0 comments
Open

Dependabot alerts for GHAE #135

github-product-roadmap opened this issue Dec 2, 2020 · 0 comments

Comments

@github-product-roadmap
Copy link
Collaborator

@github-product-roadmap github-product-roadmap commented Dec 2, 2020

Summary

Dependabot alerts send you an alert of repositories affected by a newly discovered vulnerability. This launch will add support for Dependabot alerts to GHAE.

Intended Outcome

To alert a GHAE user of a vulnerability in a dependency they use.

How will it work?

Dependabot alerts detects and alerts you when your repo has a newly discovered vulnerability. To do this, GitHub compares the information in the Dependency Graph to the information in GitHub’s Advisory Database. A security alert can either be sent when the manifest file is updated (you add a new dependency), or when a new vulnerability is discovered.

On GHAE, when enabled, the service will download the latest curated list of vulnerabilities from GitHub.com over a private channel on a regular sync. If a new vulnerability exists, the service determines the impacted users and repositories before generating alerts directly.

@github github locked and limited conversation to collaborators Dec 2, 2020
@Sid-ah Sid-ah added this to Q2 2021 – Apr-Jun in GitHub public roadmap Jan 11, 2021
@github-product-roadmap github-product-roadmap moved this from Q2 2021 – Apr-Jun to Q3 2021 – Jul-Sep in GitHub public roadmap May 12, 2021
@Sid-ah Sid-ah removed the tpm staffed label Jun 9, 2021
@github-product-roadmap github-product-roadmap moved this from Q3 2021 – Jul-Sep to Q4 2021 – Oct-Dec in GitHub public roadmap Oct 13, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
GitHub public roadmap
Q4 2021 – Oct-Dec
Status: Q4 2021 – Oct-Dec
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
2 participants