What is GitHub’s dependency graph and how does it relate to security advisories?

Github Medium

Github — Medium

What is GitHub’s dependency graph and how does it relate to security advisories?

Key points

  • Dependency graph analyzes manifest files like package.json
  • It builds a graph of direct and transitive dependencies
  • Cross-referencing with GitHub Advisory Database is key
  • Dependabot alerts notify users of vulnerable dependencies

Ready to go further?

Related questions