Informationen zu GitHub Dependabot security updates
You can enable GitHub Dependabot security updates for any repository that uses security alerts and the dependency graph. You can disable GitHub Dependabot security updates for an individual repository or for all repositories owned by your user account or organization.
When you receive a security alert about a vulnerable dependency in your repository, you can resolve the vulnerability using a security update in a pull request generated by GitHub Dependabot. Security updates are available in repositories that use the dependency graph. Standardmäßig erstellt GitHub Dependabot automatisch einen Pull Request in Ihrem Repository, um die angreifbare Abhängigkeit auf die sichere Version zu aktualisieren, die mindestens erforderlich ist, um die Schwachstelle zu vermeiden. Du kannst automatische Pull Requests auch deaktivieren und manuell Pull Requests nur dann erstellen, wenn Du Abhängigkeiten aktualisieren möchtest.
Security updates contain everything you need to quickly and safely review and merge a proposed fix into your project, including information about the vulnerability like release notes, changelog entries, and commit details.
Security updates are opened by GitHub Dependabot. GitHub Dependabot GitHub App is automatically installed on every repository where security updates are enabled.
Personen mit Zugriff auf die Sicherheitswarnungen Deines Repositorys sehen einen Link zur relevanten Sicherheitswarnung, aber andere Personen mit Zugriff auf den Pull Request können nicht sehen, welche Schwachstelle der Pull Request behebt.
When you merge a pull request that contains a security update, the corresponding security alert is marked as resolved for your repository.
Note: GitHub Dependabot security updates only resolve security vulnerabilities in your dependencies. Security updates are not created to resolve vulnerabilities in private registries or packages hosted in private repositories.
Unterstützte Repositorys
GitHub automatically enables GitHub Dependabot security updates for every repository that meets these requirements.
Note: For repositories created before November 2019, GitHub has automatically enabled GitHub Dependabot security updates if the repository meets the following criteria and has received at least one push since May 23, 2019.
| Voraussetzung | Weitere Informationen |
|---|---|
| Das Repository ist kein Fork | „Über Forks" |
| Das Repository ist nicht archiviert | „Repositorys archivieren" |
| Das Repository ist öffentlich, oder es ist privat und Du hast Nur-Lesen-Analysen durch GitHub, Abhängigkeitsdiagramme und Sicherheitswarnungen in den Repository-Einstellungen aktiviert | „Datennutzung für ein privates Repository zulassen" |
| Das Repository enthält eine Abhängigkeits-Manifestdatei aus einem Paket-Ökosystem, das GitHub unterstützt | „Unterstützte Paket-Ökosysteme" |
| GitHub Dependabot security updates are not disabled for the repository | "Managing GitHub Dependabot security updates for your repository" |
| Das Repository benutzt noch keine Integration für die Abhängigkeits-Verwaltung | „Informationen zu Integrationen“ |
If security updates are not enabled for your repository and you don't know why, you can contact support.
Informationen zu Kompatibilitätsbewertungen
GitHub Dependabot security updates also include compatibility scores to let you know whether updating a vulnerability could cause breaking changes to your project. We look at previously-passing CI tests from public repositories where we've generated a given security update to learn whether the update causes tests to fail. Die Kompatibilitätsbewertung eines Update ist der Prozentsatz an CI-Ausführungen, die beim Aktualisieren zwischen relevanten Versionen der Abhängigkeit bestanden wurden.
Managing GitHub Dependabot security updates for your repository
You can enable or disable GitHub Dependabot security updates for an individual repository.
GitHub Dependabot security updates require specific repository settings. Weitere Informationen findest Du unter „Unterstützte Repositorys."
- Navigiere in GitHub zur Hauptseite des Repository.
- Klicke unter Deinem Repository-Namen auf Security (Sicherheit).

- In the security sidebar, click Dependabot alerts.

- Above the list of alerts, use the drop-down menu and select or unselect Dependabot security updates.

Managing GitHub Dependabot security updates for your user account
You can disable GitHub Dependabot security updates for all repositories owned by your user account. If you do, you can still enable GitHub Dependabot security updates for individual repositories owned by your user account.
- Klicke in der oberen rechten Ecke einer beliebigen Seite auf Dein Profilfoto und klicke dann auf Settings (Einstellungen).

- Klicke in der Seitenleiste für Benutzereinstellungen auf Security (Sicherheit).

- Under "Dependabot security updates", select or deselect Opt out of Dependabot security updates.

- Klicken Sie auf Save (Speichern).
Managing GitHub Dependabot security updates for your organization
Organization owners can disable GitHub Dependabot security updates for all repositories owned by the organization. If you do, anyone with admin permissions to an individual repository owned by the organization can still enable GitHub Dependabot security updates on that repository.
- In der oberen rechten Ecke von GitHub klicke auf Dein Profilfoto und dann auf your profile (Dein Profil).

- Klicke auf der linken Seite Deiner Profilseite unter „Organizations" (Organisationen) auf das Symbol für Deine Organisation.

- Klicke unter Deinem Organisationsnamen auf Settings (Einstellungen).

- In der Seitenleiste für Organisationseinstellungen klicke auf Security (Sicherheit).

- Under "Dependabot security updates", select or deselect Opt out of Dependabot security updates.

- Klicken Sie auf Save (Speichern).