[dep-ecosystem] Dependency Report — 2026-03-01 #26
Replies: 1 comment
-
|
This issue has been automatically marked as stale because it has not had activity in the last 30 days. It will be closed in 30 days if no further activity occurs. To keep this open:
|
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Monitored: 101 repositories | Excluded: php-swagger, swagger-php
Executive Summary
All 23 open Dependabot PRs were opened on 2026-03-01 — none have exceeded the 14-day staleness threshold.
Language Distribution
Dependabot PR Summary
adrscopeatlatl-specatlatlrlm-rslro-bench.githubvscode-git-adrdaedalussubcoggithub-project-managerRepositories with zero open Dependabot PRs (91 repos)
Hal, chef-composer, Bloom, rlm-rs-plugin, Rhubarb, subcog-enterprise, ApiProblem, Uuid, mnemonic, svelte-lsp, agents, git-adr, sigint, oolong-pairs, human-voice, lsp-marketplace, nsip-example, claude-team-orchestration, github-social, adr, documentation-review, python-lsp, nsip, MIF, gh, lsp-tools, structured-madr, yaml-lsp, aesth, ccpkg, auto-harness, version-guard, rust-lsp, json-lsp, maker-rs, kotlin-lsp, notebook-template, haskell-lsp, content-pipeline-template, docs-site-template, csharp-lsp, claude-plugin-template, vue-lsp, dockerfile-lsp, go-lsp, atlatl-spec (zero-PR note: this repo has 4 open PRs — see above), ruby-lsp, html-css-lsp, data-science-template, project-planning-template, farm-notebook-examples, java-lsp, typescript-template, github-agentic-workflows, tone-police, sql-lsp, lua-lsp, zig-lsp, github4farms, php-lsp, elixir-lsp, bash-lsp, python-template, rust-template, graphql-lsp, markdown-lsp, memory-benchmark-harness, typescript-lsp, devcontainer-template, swift-lsp, scala-lsp, latex-lsp, sdlc-quality, github4farms-training, java-template, nsip-plugin, gh-agentic-workflows, terraform-lsp, go-template, cpp-lsp, ghe-migration, memory-capture-plugin, IncidentAI, refactor, lro-bench (zero-PR note: this repo has 2 open PRs — see above), video-template, gh-aw-trial, prompts, github-migration, github, github-project-manager (zero-PR note: see above), video-production
Version Consistency Findings
Rust Ecosystem
Version consistency analysis was performed using available Dependabot PR data and public repository manifests. The following shared Cargo crates were identified across public Rust repositories:
serdetempfileclap¹ Direct file content read was not available for private repositories; exact version strings could not be compared. No inconsistencies were observed in the open Dependabot PR set (all bumps target consistent versions).
² adrscope
tempfilewas 3.25.0 prior to the current open PR (#40) bumping it to 3.26.0.Python Ecosystem
All repos using SHA
9198f8defor theirdependabot.ymlshare the same pip + github-actions configuration template. Exactpyproject.tomldependency versions were not directly comparable due to API content limitations. No cross-repo Python version bump PRs are currently open.All Python repositories are assumed version-consistent pending direct manifest inspection.
Node/TypeScript Ecosystem
atlatlhas an open PR (#59) bumpingjsonwebtokenfrom 9.3.1 → 10.3.0 (major version bump). Other TypeScript/JS repos (vscode-git-adr, typescript-lsp, typescript-template, IncidentAI) did not show shared npm dependency inconsistencies in the open PR set.All Node/TypeScript repositories are assumed version-consistent pending direct manifest inspection.
Coverage Gaps
IncidentAInpm,github-actionsproject-planning-templatenpm,github-actionsgh-aw-trialgithub-actionsgh-agentic-workflowsgithub-actionspromptsgithub-actionsgithubnpm,github-actions(in templates)github-actionsat root.githubgithub-actionsgithub-actionsreview for reusable workflowsgo-templategithub-actionsgomodif go.mod is presenttypescript-templatenpmis configuredEcosystem Configuration Summary (inferred from blob SHA groupings and code search):
d6b9ee127dd7b39198f8d31f144b33607eff75e00Dependency Health Scores
adrscopeatlatl-specatlatlrlm-rs.githublro-benchvscode-git-adrdaedalussubcoggithub-project-managerIncidentAIproject-planning-templategh-aw-trialgh-agentic-workflowspromptsGrade distribution: A: 86 repos | B: 5 repos | C: 4 repos | D: 5 repos | F: 0 repos
Recommended Actions
IncidentAI— TypeScript repo with no dependency monitoring. Recommendnpm+github-actionsconfiguration.project-planning-template— JavaScript repo, unmonitored. Recommendnpm+github-actions.gh-aw-trial,gh-agentic-workflows,prompts— Unknown language repos missing dependabot; at minimum addgithub-actionsmonitoring if they contain workflow files.atlatlPR [Alert] Smart Alerts — 2026-03-02 (Run #22571173123) #59 —jsonwebtoken9.3.1 → 10.3.0 is a major version bump that may include breaking changes; review carefully before merging.adrscope— 5 open PRs, highest backlog in the org; bulk-merge the actions bumps.githubrepo — Currently only has configs in template subdirectories.Generated by dependency-ecosystem workflow — https://github.com/zircote/.github/actions/runs/22548331240
Beta Was this translation helpful? Give feedback.
All reactions