Vovy turns on Dependabot alerts and security updates, reviews the pull requests it opens, and merges the safe ones after checks pass.
Turn on Dependabot and fix the security alerts on my repo
How it works
- Turn on Dependabot: Vovy opens Settings, Advanced Security and enables Dependabot alerts and security updates. Dependabot watches your packages for known security holes.
- Read the alerts: Vovy lists every alert as a table card by severity, with a plain-English line on what the risk is for your app.
- Review the fix PRs: Dependabot opens pull requests that bump each package. Vovy checks each one's changelog for breaking changes.
- Test and merge: Vovy waits for your checks and preview to pass, then merges the safe updates.
- Show what is left: A card lists fixed alerts, ones that need a manual upgrade, and ones that do not affect your app.
What you provide
- Admin access to the repo
- Checks or a preview to test updates
What you get
- Dependabot turned on
- Alerts explained by real risk
- Safe updates merged
- A list of what still needs work
FAQ
Is Dependabot free?
Yes, Dependabot alerts and security updates are free on GitHub for public and private repos.
Will updates break my app?
Occasionally, especially major version bumps. That is why Vovy waits for your build and preview before merging.
It's flooding me with PRs.
You can group updates or set a weekly schedule in .github/dependabot.yml to cut the noise.
Related tasks
All tasks