Skip to content

docs: record dependency graph and Dependabot settings#99

Merged
CoderDeltaLAN merged 1 commit into
mainfrom
security/evaluate-dependabot-dependency-graph
Jun 19, 2026
Merged

docs: record dependency graph and Dependabot settings#99
CoderDeltaLAN merged 1 commit into
mainfrom
security/evaluate-dependabot-dependency-graph

Conversation

@CoderDeltaLAN

Copy link
Copy Markdown
Owner

Records manual GitHub Advanced Security UI evidence for dependency graph and Dependabot-related settings after the v0.3.0 hardening train.

Scope:

  • Add a dedicated dependency graph and Dependabot settings record.
  • Update the supply-chain evaluation document so it no longer carries stale private vulnerability reporting wording.
  • Document deferred boundaries for Dependabot version updates and automatic dependency submission.

Out of scope:

  • No .github/dependabot.yml.
  • No Dependabot version updates.
  • No release, tag, PyPI, branch protection, CI, or runtime behavior changes.
  • No claim that malware alerts or grouped security updates are enabled unless later verified by UI evidence.

Local verification completed before push:

  • ./scripts/check.sh passed.
  • 142 unit tests passed.
  • ruff passed.
  • text hygiene passed.
  • git whitespace checks passed.
  • staged content guards passed.
  • safety scan found no obvious secret patterns.

@CoderDeltaLAN CoderDeltaLAN merged commit 73f1682 into main Jun 19, 2026
4 checks passed
@CoderDeltaLAN CoderDeltaLAN deleted the security/evaluate-dependabot-dependency-graph branch June 19, 2026 09:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant