GitHub Dependabot Alertを有効化したらRenovateが対象のPRを投げてくれる
Dependabot Alertを有効化するだけで、RenovateがセキュリティPRを投げてくれるようになる
入力して検索を開始
Dependabot Alertを有効化するだけで、RenovateがセキュリティPRを投げてくれるようになる
Dependabot Alertを有効化するだけで、RenovateがセキュリティPRを投げてくれるようになる
GitHub Advisory Database 照合による opt-in の malware アラート。CVE 系とは別カテゴリ、ルールによる絞り込み、有効化時の既存分バックフィル。現状 npm のみ。
write 権限ユーザーへの割当、code scanning・secret scanning アラートと同じ運用。REST API・Webhook、監査ログとメール通知。github.com は GHAS、GHES は3.22以降。
uvの依存関係に脆弱性が検出された際、アラート発行と更新PRの自動作成が可能に。
Hi there. I'm hrdtbs, a frontend expert and technical consultant. I started my career in the creative industry over 13 years ago, learning on the job as a 3DCG modeler and game engineer in the indie scene.
In 2015 I began working as a freelance web designer and engineer. I handled everything from design and development to operation and advertising, delivering comprehensive solutions for various clients.
In 2016 I joined Wemotion as CTO, where I built the engineering team from the ground up and led the development of core web and mobile applications for three years.
In 2019 I joined matsuri technologies as a Frontend Expert, and in 2020 I also began serving as a technical manager supporting streamers and content creators.
I'm so grateful to be working in this field, doing something that brings me so much joy. Thanks for stopping by.