Skip to content

dependabot vs. dependabot-preview - detecting security vulnerabilities #22520

Discussion options

You must be logged in to vote

The dependabot-preview product isn’t related to the vulnerability alerts system. It’s used specifically to keep dependencies up-to-date, whether for security reasons or not. Since it isn’t hooked in to GitHub’s vulnerability alerts system, you are correct that it won’t catch some things that the vulnerability alerts system will.

As for what’s recommended for a security audit, GitHub’s security features, such as security alerts, do not claim to catch all vulnerabilities. Though we are always trying to update our vulnerability database and alert you with our most up-to-date information, we will not be able to catch everything or alert you to known vulnerabilities within a guaranteed time fr…

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
3 participants