You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
✅ No security vulnerabilities detected across the organization this week.
Language Distribution
Language
Repos
Percentage
Python
10
13.2%
Rust
7
9.2%
PHP (legacy)
6
7.9%
MDX / Markdown
4
5.3%
TypeScript
2
2.6%
Ruby
2
2.6%
Shell
3
3.9%
JavaScript
1
1.3%
Go
1
1.3%
Java
1
1.3%
Other (Svelte, Elixir, Swift, TeX, Scala)
5
6.6%
No primary language / config-only
34
44.7%
Total
76
100%
Note: Many repos are Claude Code plugins, LSP integrations, and specification documents with no compiled language. Language detection uses GitHub's primary language field.
⚠️rmcp divergence detected:atlatl is running rmcp v0.17.0 while subcog is at v1.1.1 — a major version gap (1+ major versions behind). Atlatl's pending Dependabot PR (#84) targets v1.1.0 as its first step but still requires a follow-up bump to reach parity with subcog at v1.2.0. Both repos use this MCP communication library, so API compatibility divergence could cause integration issues.
Node/TypeScript Ecosystem
Dependency
atlatl-spec
docs-site-template
Consistent?
@astrojs/starlight
0.37.7
0.37.7
✅
astro
5.18.0
—
—
All Node/TypeScript repositories are otherwise version-consistent within observed shared dependencies.
GitHub Actions Ecosystem
Common actions (actions/checkout, actions/upload-artifact, actions/download-artifact, docker/*) show consistent pending target versions across all repositories — all bumping to the same latest versions. No cross-repo action version divergence detected.
Coverage Gaps
Repository
Language
Has dependabot.yml?
Configured Ecosystems
Recommended Ecosystems
autoresearch
Python
❌
—
pip, github-actions
All other 75 monitored repositories have a .github/dependabot.yml file present.
Merge stale PRs immediately — All 4 stale PRs are CI/actions bumps with no breaking changes. Priority: github-migration#1 (attest-build-provenance v3→v4) and the two adrscope SHA pin updates.
Resolve rmcp divergence — After merging atlatl#84 (0.17.0→1.1.0), add a follow-up bump to reach v1.2.0 parity with subcog.
Add dependabot.yml to autoresearch — Copy the Python template config (pip + github-actions ecosystems).
Triage daedalus and adrscope backlogs — Both repos have 6-7 open PRs. Consider enabling Dependabot auto-merge for low-risk patch/minor CI bumps.
Review astro v5→v6 major bump in atlatl-spec — Major version bump requires manual validation before merging.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
-
Monitored: 76 repositories | Excluded: php-swagger, swagger-php
Executive Summary
Language Distribution
Dependabot PR Summary
daedalusadrscopelro-benchgithub-migrationmaker-rs.githubatlatl-specdocs-site-templatecontent-pipeline-templateatlatlmemory-benchmark-harnesssubcogccpkgsubcog-enterprisejava-templatenotebook-templatedata-science-templatepython-templategithub-project-managertypescript-templaterlm-rsMIFstructured-madrStale PRs requiring attention (> 14 days old):
Repositories with zero open Dependabot PRs (53 repos)
mnemonic, git-adr, nsip, rust-lsp, Hal, Bloom, Rhubarb, ApiProblem, Uuid, agents, human-voice, vscode-git-adr, autoresearch, claude-spec-benchmark, homebrew-tap, go-lsp, java-lsp, typescript-lsp, refactor, oolong-pairs, python-lsp, tone-police, rust-template, rlm-rs-plugin, nsip-plugin, elixir-lsp, swift-lsp, chef-composer, sigint, nsip-example, memory-capture-plugin, lsp-marketplace, gh, svelte-lsp, scala-lsp, latex-lsp, bash-lsp, graphql-lsp, github4farms-training, lsp-marketplace, php-lsp, java-lsp, go-lsp, typescript-lsp, mnemonic, python-lsp, nsip-plugin, tone-police, scala-lsp, lsp-marketplace, swift-lsp, elixir-lsp, bash-lsp
Version Consistency Findings
Rust Ecosystem
subcogatlatldaedalusadrscopermcpclaptempfileNode/TypeScript Ecosystem
atlatl-specdocs-site-template@astrojs/starlightastroAll Node/TypeScript repositories are otherwise version-consistent within observed shared dependencies.
GitHub Actions Ecosystem
Common actions (
actions/checkout,actions/upload-artifact,actions/download-artifact,docker/*) show consistent pending target versions across all repositories — all bumping to the same latest versions. No cross-repo action version divergence detected.Coverage Gaps
autoresearchpip,github-actionsAll other 75 monitored repositories have a
.github/dependabot.ymlfile present.Ecosystem configuration patterns observed:
cargo+github-actionsnpm+github-actionspip+github-actionsgithub-actionsonlygithub-actionsonly (no composer configured — low priority given inactivity)Dependency Health Scores
daedalusadrscopeautoresearchlro-benchgithub-migrationcontent-pipeline-templatemaker-rs.githubatlatl-specdocs-site-template@astrojs/mdxmajor bump pendingatlatlmemory-benchmark-harnesssubcogccpkgsubcog-enterprisejava-templatenotebook-templatedata-science-templatepython-templategithub-project-managertypescript-templaterlm-rsMIFstructured-madrGrade distribution: A: 52 | B: 14 | C: 7 | D: 3 | F: 0
Recommendations
github-migration#1(attest-build-provenance v3→v4) and the twoadrscopeSHA pin updates.rmcpdivergence — After mergingatlatl#84(0.17.0→1.1.0), add a follow-up bump to reach v1.2.0 parity withsubcog.dependabot.ymltoautoresearch— Copy the Python template config (pip+github-actionsecosystems).daedalusandadrscopebacklogs — Both repos have 6-7 open PRs. Consider enabling Dependabot auto-merge for low-risk patch/minor CI bumps.astrov5→v6 major bump inatlatl-spec— Major version bump requires manual validation before merging.Generated by dependency-ecosystem workflow — https://github.com/zircote/.github/actions/runs/23408198396
Beta Was this translation helpful? Give feedback.
All reactions