Github — Medium
Key points
- Dependency graph analyzes manifest files like package.json
- It builds a graph of direct and transitive dependencies
- Cross-referencing with GitHub Advisory Database is key
- Dependabot alerts notify users of vulnerable dependencies
Ready to go further?
Related questions
