Dependabot

Dependabot Security Updates and Alerts

The dependency graph reads BookNest's manifests and lockfile; Dependabot 29 alerts match it against the GitHub 29 Advisory Database and flag any installed version inside a vulnerable range; security updates then open a pull request that raises that one dependency to the lowest patched version, even between scheduled version updates. The first two are switched on per repository, and the graph is already on for public ones:

Turning on Dependabot alerts and security updatesShell
gh api -X PUT repos/{owner}/{repo}/vulnerability-alerts
gh api -X PUT repos/{owner}/{repo}/automated-security-fixes
gh api repos/{owner}/{repo}/automated-security-fixes
gh api repos/{owner}/{repo}/dependency-graph/sbom --jq '.sbom.packages | length'
gh api repos/{owner}/{repo}/dependabot/alerts --jq length
Output
{"enabled":true,"paused":false}94
{"message":"Resource not accessible by personal access token",...,"status":"403"}gh: Resource
not accessible by personal access token (HTTP 403)

The graph's SPDX bill of materials lists 94 packages: two direct dependencies, everything they pull in, and the workflows' actions. Listing alerts needs the Dependabot alerts permission this token lacks (403), so that is not run here; the nightly npm 2,036 audit (Scheduled Workflows with cron) had found 0 vulnerabilities. Unlike npm audit (MERN Stack Development), Dependabot watches continuously and alerts when an advisory is published. Alerts can be dismissed with a reason or by auto-triage rules, and a security update's pull request passes the same rulesets and required checks as anyone's, so a patch that breaks the tests does not merge.