Skip to content
CAI
Software that uses CAICheck a score

dependabot/dependabot-core

44.6

Weak · 7 August 2026

152.8k

lines of production code

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This release delivers extensive new ecosystem support for Bun, Julia, Conda, OpenTofu, Dev Containers, and Swift, while introducing native helpers for Go, NuGet, and Python's uv. A major architectural shift involves refactoring core libraries—Bundler, Cargo, and Composer—into modular, strictly typed components to improve maintainability and type safety. Additionally, the system now supports private registries for Docker images, Git submodules, and Azure/Bitbucket/CodeCommit platforms, alongside significant improvements to error handling and CI testing infrastructure.

Features

Add Bun lockfile and package.json update support

Introduces new classes to handle Bun dependency updates: \BunLockfileUpdater\ orchestrates the update process by generating \.npmrc\ configuration and executing \bun install\ commands; \NpmrcBuilder\ constructs the \.npmrc\ file from registry credentials and lockfile data; \PackageJsonPreparer\ sanitizes \package.json\ content by converting SSH git sources to HTTPS and removing invalid characters; and \PackageJsonUpdater\ applies version changes to \package.json\ and its \resolutions\ section. These changes enable Dependabot to manage Bun-based projects by updating lockfiles and package manifests.

_bun/lib/dependabot/bun/file\updater · high confidence

Add Bun lockfile parsing support

Introduces new parsers for the Bun package manager, enabling Dependabot to read \bun.lock\ lockfiles and extract dependency metadata. The implementation includes \BunLock\ for parsing the lockfile content and \LockfileParser\ to orchestrate the extraction, allowing the system to track Bun dependencies alongside existing npm/yarn support.

_bun/lib/dependabot/bun/file\parser · high confidence

Add Bundler PackageDetailsFetcher for private registry support

A new \PackageDetailsFetcher\ class has been introduced for the Bundler package manager, enabling the system to fetch package version details from private registries. The implementation includes robust error handling for invalid JSON responses and ensures that dependencies sourced from 'git' or 'other' return \nil\ rather than attempting to query RubyGems. This change supports private registry cooldown functionality and improves error reporting for failed fetches.

bundler/lib/dependabot/bundler/package · medium confidence

Add Composer package details fetcher

A new \PackageDetailsFetcher\ class has been introduced for the Composer package manager. This component is responsible for retrieving and parsing package metadata and release information from various registries, including support for both v1 and v2 API formats. It handles credential-based authentication for private registries and manages the logic for fetching version details, which is essential for accurate dependency updates.

bun/lib/dependabot/bun/package, cargo/lib/dependabot/cargo/package, composer/lib/dependabot/composer/package · high confidence

Add GitHub Actions ecosystem support with lockfile integration

Introduces a new \github\_actions\ ecosystem to detect, update, and manage GitHub Actions dependencies. This includes a file fetcher and parser that identify actions in workflow YAML files, an update checker that resolves versions via git tags, and a file updater that rewrites workflow files with new refs. A key addition is the integration with the \gh-actions-lock\ tool to generate and maintain an \actions.lock\ lockfile, ensuring that updates respect the authoritative state of the repository's actions. The implementation includes a dedicated Dockerfile, configuration files, and Sorbet type annotations.

_github\actions · high confidence

Add Nix ecosystem support for updating flake.lock and channel tarball inputs

Users can now have Dependabot monitor and update Nix flake dependencies. This adds full support for Git-backed flake inputs (GitHub, GitLab, SourceHut, and generic Git), NixOS channel tarball inputs (with automatic revision resolution), and indirect registry shorthands. The update process runs \nix flake update\ to regenerate the lockfile, and the system correctly handles versioned branches, tag-based pins, and channel versioning with ignore filters.

nix · high confidence

Add OpenTofu ecosystem support

Introduces a new OpenTofu ecosystem to Dependabot, enabling the detection, parsing, and updating of OpenTofu configuration files (.tf, .tofu, .hcl) and Terragrunt files. The implementation includes a file fetcher to locate and filter relevant configuration files, a parser to extract dependencies from modules, providers, and local paths, and an updater to modify version constraints in the source files. It also supports OCI modules, Git-based modules, and registry-hosted modules, with metadata and version resolution logic integrated into the existing Dependabot pipeline.

(repo-wide) · high confidence

Add PullRequestUpdater implementations for Azure, GitHub, and GitLab

The \common/lib/dependabot/pull\_request\_updater\ directory now includes new \Azure\, \Github\, and \Gitlab\ classes that implement the \PullRequestUpdater\ interface. These classes handle updating pull requests by creating commits and updating branch references for their respective platforms, supporting features like author details, signature keys, and target project IDs.

_common/lib/dependabot/pull\_request\updater · high confidence

Add Rust/Cargo package manager support

Added the core implementation for the Rust/Cargo package manager, including file fetching, parsing, updating, and metadata finding. The new \cargo.rb\ file registers the Cargo file fetcher, parser, update checker, file updater, and metadata finder. It also registers the 'rust' label for pull requests and sets up a production check for Cargo dependencies.

cargo/lib/dependabot · high confidence

Add Swift ecosystem support for Dependabot

Introduces a new Swift package manager integration, enabling Dependabot to fetch, parse, and update Swift dependencies. The implementation supports both classic SPM projects (via Package.swift) and Xcode-managed SwiftPM projects (via Package.resolved and project.pbxproj files). It includes a FileFetcher to locate and retrieve dependency files, a FileParser to extract dependency metadata, and a FileUpdater to modify lockfiles and project files. The Dockerfile sets up the Swift 6.3.1 runtime, and the lib/ directory contains the core logic for parsing and updating Swift dependencies.

swift · high confidence

Add VS Code Remote Development on Docker devcontainer

The .devcontainer directory now contains the configuration files (Dockerfile, devcontainer.json, and shell scripts) required to run the project in a VS Code Remote Container. This provides a pre-configured development environment with Ubuntu, Ruby 4.0.5, .NET 8/9/10 SDKs, Node.js, Go, Rust, and relevant VS Code extensions, streamlining the setup process for new contributors and CI environments.

.devcontainer · high confidence

Add initial plumbing for the Dev Containers package manager

A new \devcontainers\ package manager is registered within the Dependabot library, including the file fetcher, parser, update checker, file updater, metadata finder, requirement, and version classes. The entry point registers the package manager with the pull request creator's labeler and configures the dependency production check to always return true, enabling Dependabot to process \devcontainers\ dependencies.

devcontainers/lib/dependabot · high confidence

Add initial support for the devcontainers ecosystem

Users can now have their devcontainer.json files scanned for dependency updates. This change introduces the full plumbing for the devcontainers ecosystem, including file fetching, parsing, updating, and version checking, allowing Dependabot to detect and propose updates for dev container configurations.

devcontainers/lib/dependabot/devcontainers · high confidence

Add native Conda ecosystem support

Introduced a complete, native implementation for the Conda package manager ecosystem. This includes a registry client to fetch package metadata from anaconda.org, a file fetcher to process environment.yml files, a parser to extract dependencies, an updater to modify environment files, and a metadata finder to resolve package details. The implementation supports simplified Conda version constraints and pip dependencies within environment files, while explicitly rejecting fully qualified specifications with build strings. This enables Dependabot to monitor and update Conda-based projects.

conda/lib/dependabot/conda · high confidence

Add native JavaScript helpers for Bun, npm, pnpm, and Yarn

This change introduces a new \bun/helpers\ directory containing native JavaScript helper functions for various package managers. For npm, it adds a \conflicting-dependency-parser\ and a \vulnerability-auditor\ that use \@npmcli/arborist\ to detect dependency conflicts and audit for security vulnerabilities. For npm 6, it provides utilities to update dependencies, check peer dependencies, and manage lockfiles. For pnpm, it adds a lockfile parser. For Yarn, it includes a \conflicting-dependency-parser\, a \fix-duplicates\ utility, and helpers for updating dependencies and lockfiles. These helpers are designed to be called from Ruby code via \run.js\, passing arguments via stdin and returning JSON to stdout, allowing the system to utilize package managers' internal APIs and native tooling.

bun/helpers · high confidence

Add native helper for Bundler 4 support

Introduces a new \bundler/helpers/v4\ directory containing a dedicated native helper tree for Bundler 4. This includes a build script that installs and isolates Bundler 4.x, along with Ruby modules for resolving version constraints, parsing Gemfiles and lockfiles, updating lockfiles, and identifying conflicting dependencies. The helper also applies monkey patches to handle Bundler 4 API changes, such as \Index\#search\_all\ removal, Git source authentication, and empty checksum metadata handling.

bundler/helpers/v4 · high confidence

Add sbt ecosystem support for dependency updates

Users can now have their SBT (Scala Build Tool) projects scanned and updated by Dependabot. This change introduces the full implementation for the \sbt\ ecosystem, including file fetching, parsing, updating, and metadata finding. The implementation leverages Coursier for native dependency resolution and supports resolving dependencies defined via Scala \val\ references in \build.sbt\ and \project/\ files. It also handles SBT plugin cross-versioning and custom Maven repository resolvers.

sbt · high confidence

Add support for .NET SDK version updates

Introduce a new \dotnet\_sdk\ ecosystem that enables Dependabot to detect, parse, and update \.NET SDK\ versions specified in \global.json\ files. This includes a file fetcher to locate \global.json\, a parser to extract SDK version and metadata (such as \allowPrerelease\ and \rollForward\), an update checker that queries the official .NET release metadata for the latest versions, and an updater that modifies the \global.json\ file. The implementation also includes a custom version class to handle .NET's non-semver versioning scheme and metadata finding to link to the .NET SDK GitHub repository.

_dotnet\sdk/lib · high confidence

Add support for Azure, Bitbucket, CodeCommit, and template-based branch naming

The PullRequestCreator now supports creating pull requests on Azure DevOps, Bitbucket, and AWS CodeCommit, in addition to the existing GitHub and GitLab integrations. Each new provider (Azure, Bitbucket, CodeCommit) includes its own creator class handling commit and pull request creation with platform-specific limits and behaviors. Additionally, a new BranchNameTemplate class and BranchNamer refactoring introduce configurable branch naming strategies (solo, group, multi-ecosystem) with template-based naming, allowing users to customize branch name formats and enforce stricter validation rules for branch names.

_common/lib/dependabot/pull\_request\creator · high confidence

Add support for Git submodules

The \git\_submodules\ directory now contains the complete implementation for the Git submodules ecosystem, including file fetching, parsing, updating, and metadata finding. This adds the ability for Dependabot to detect, parse, and update dependencies defined in \.gitmodules\ files across GitHub, GitLab, and Azure repositories. The implementation includes a \PackageDetailsFetcher\ to retrieve available versions and a \LatestVersionFinder\ that respects cooldown periods. Tests are provided for all components.

_git\submodules · high confidence

Add support for Rust toolchain updates

Dependabot can now manage Rust toolchain dependencies. This adds a new \rust\_toolchain\ updater that detects \rust-toolchain\ and \rust-toolchain.toml\ files, parses version or channel specifications (such as \stable\, \beta\, \nightly\, or specific versions like \1.72.0\), and generates pull requests to update them to the latest available release.

_rust\toolchain · high confidence

Add support for parsing PEP 735 dependency groups and UV tool sources

The \uv/helpers\ module now includes new helper functions to parse \pyproject.toml\ files, specifically supporting PEP 735 dependency groups and \tool.uv\ path sources. The \parser.py\ file was added to handle these new TOML sections, while \hasher.py\ was added to manage dependency hashing. These changes enable the tool to correctly identify and process optional and build-system dependencies defined in modern Python project configurations.

uv/helpers · high confidence

Add support for parsing devcontainer feature dependencies

The Dependabot parser for the devcontainers ecosystem now extracts feature dependencies from devcontainer configuration files. The new \FeatureDependencyParser\ invokes the \devcontainer\ CLI to identify outdated features, filtering out SHA-pinned versions and deprecated features. This enables Dependabot to track and propose updates for devcontainer features alongside other dependency types.

_devcontainers/lib/dependabot/devcontainers/file\parser · high confidence

Add support for the Dart (pub) ecosystem

Introduces a new \pub\ ecosystem integration for Dart packages. This includes the core Ruby classes for file fetching, parsing, updating, and metadata finding, along with native Dart helpers for dependency services and SDK version inference. The update checker now supports security updates, version resolution, and requirements updates specific to the pub package manager.

pub · high confidence

Add support for the vcpkg package manager

Dependabot can now manage dependencies for the vcpkg C++ package manager. This adds support for updating the \builtin-baseline\ in \vcpkg.json\, managing \default-registry\ and \registries\ in \vcpkg-configuration.json\, and updating port \version\>=\ constraints. The implementation includes a Dockerfile to install vcpkg in the updater image, along with the necessary Ruby classes for file fetching, parsing, updating, and metadata finding. Security updates for vcpkg ports are also supported, with the system capable of raising baselines, adding version constraints, or applying overrides to fix vulnerabilities.

(repo-wide) · high confidence

Add support for updating Helm charts and container images

Dependabot can now manage updates for Helm charts and container images defined in Helm \Chart.yaml\ and \values.yaml\ files. This includes parsing dependencies from Helm chart files, updating version constraints in \Chart.yaml\, and updating image tags in \values.yaml\. The implementation adds new files for fetching, parsing, and updating Helm dependencies, along with helper utilities for interacting with Helm and OCI registries.

helm · high confidence

Add support for updating pre-commit additional dependencies

Users can now have Dependabot update \additional\_dependencies\ in pre-commit hook configurations. This change introduces a new architecture for handling language-specific dependencies (Python, Node, Go, Ruby, Rust, and Dart) within pre-commit hooks, allowing Dependabot to detect and update these transitive dependencies alongside the main hook versions.

_pre\commit · high confidence

Add v2 monkey patches for Bundler compatibility

Added four new monkey patches in the v2 Bundler helper to improve compatibility and fix issues with upstream Bundler behavior. The \definition\_bundler\_version\_patch\ prevents the helper from failing when the Gemfile specifies a Bundler version that differs from the one in use. The \definition\_ruby\_version\_patch\ enables the helper to read the Ruby version from a \.ruby-version\ file and inject it into the dependency resolution process. The \endpoint\_specification\_metadata\_patch\ prevents resolution failures caused by empty checksum metadata in registry responses. The \git\_source\_patch\ converts SSH-based GitHub URLs to HTTPS to avoid authentication issues, and ensures gemspecs in git sources are properly evaluated and cached.

_bundler/helpers/v2/monkey\patches · high confidence

Added Bazel file update support for Bzlmod and Workspace files

Users can now have Bazel dependencies updated via Dependabot. This change introduces new updaters for \bzlmod\ (MODULE.bazel) and \workspace\ (WORKSPACE) files. The \BzlmodFileUpdater\ handles updates to \bazel\_dep\ declarations and generates or updates \MODULE.bazel.lock\ lockfiles by invoking \bazel mod tidy\. The \WorkspaceFileUpdater\ updates \http\_archive\ and \git\_repository\ declarations in \WORKSPACE\ files. A \DeclarationParser\ is also added to parse Bazel build file declarations.

_bazel/lib/dependabot/bazel/file\updater · high confidence

Added Bazel update checker and requirements updater

A new Bazel ecosystem is now supported, introducing a RegistryClient to fetch module metadata and versions from the bazel-central-registry, and a RequirementsUpdater to manage dependency version updates. This enables Dependabot to monitor and update Bazel-based projects.

_bazel/lib/dependabot/bazel/update\checker · high confidence

Added Elm package details fetcher

A new PackageDetailsFetcher class has been introduced for the Elm ecosystem, enabling the system to retrieve and parse package release information from the Elm package registry. This addition supports the broader refactor to implement cooldown logic for package fetching, allowing Dependabot to access detailed release metadata for Elm packages.

elm/lib/dependabot/elm/package · high confidence

Added GemNetHttpAdapter for WebMock integration

A new adapter class, GemNetHttpAdapter, has been added to the spec helpers to enable WebMock to intercept and mock requests made by Ruby's standard library Gem::Net::HTTP. This allows tests to simulate HTTP responses without making real network calls, improving test isolation and speed.

_bundler/helpers/spec\helpers · high confidence

Added lockfile generation for Bun dependency graphing

A new LockfileGenerator class has been introduced for the Bun package manager, enabling the system to automatically generate a bun.lock file during dependency graphing. The generator writes package.json and .npmrc files to a temporary directory, then executes 'bun install' to produce the lockfile. Notably, if no .npmrc file is present in the repository, the generator creates one from stored credentials, ensuring that private registry authentication is handled automatically during the graphing process.

_bun/lib/dependabot/bun/dependency\grapher · high confidence

Added package details fetching for Dev Containers ecosystem

A new \PackageDetailsFetcher\ class has been introduced for the Dev Containers ecosystem. This component is responsible for retrieving package release information and metadata by executing the \devcontainer features info tags\ command and querying container registries (such as GitHub Container Registry) to fetch version and release date details for packages.

devcontainers/lib/dependabot/devcontainers/package · high confidence

Added support for private registries and Helm chart detection

Users can now authenticate with private Docker registries, including AWS ECR, via the new CredentialsFinder utility which handles registry-specific credential resolution and AWS token generation. Additionally, the system can now detect Helm chart files by recognizing filenames matching the pattern 'values\.yaml' or 'values\.yml' through the new likely\_helm\_chart? helper.

docker/lib/dependabot/shared/utils · high confidence

Added support for the Bun package manager

A new implementation for the Bun package manager has been added to Dependabot. This includes the core Ruby classes for file fetching, parsing, updating, and error handling, along with registration in the package manager lookup table. Users can now use Dependabot to manage dependencies for Bun-based projects.

bazel/lib/dependabot, bun/lib/dependabot · high confidence

Bun ecosystem support for update checking

Added new classes to support the Bun package manager ecosystem, including \ConflictingDependencyResolver\, \DependencyFilesBuilder\, \LatestVersionFinder\, \LibraryDetector\, \RequirementsUpdater\, \SubdependencyVersionResolver\, \VersionResolver\, and \VulnerabilityAuditor\. These components enable Dependabot to detect dependency conflicts, resolve versions, update requirements, and audit for vulnerabilities specifically for Bun projects.

_bun/lib/dependabot/bun/update\checker · high confidence

Centralized dependency management for all supported ecosystems

The \omnibus\ gem has been introduced to serve as a central registry that requires and exposes all supported package manager ecosystems (including Bazel, Bun, Conda, Deno, Docker, Julia, Nix, OpenTofu, and others). This change consolidates access to every ecosystem's functionality through a single entry point, ensuring that all supported package managers are loaded and available for use.

omnibus · high confidence

Composer ecosystem implementation for PHP dependency management

Added the core components for the Composer ecosystem, including file fetching, parsing, updating, and metadata finding. This enables Dependabot to manage PHP dependencies by reading composer.json and composer.lock files, detecting package and PHP versions, and identifying security vulnerabilities. The implementation includes strict typing with Sorbet, support for artifact and path dependencies, and integration with Packagist for version resolution.

composer/lib/dependabot/composer · high confidence

Docker ecosystem support added

Added support for Docker images as a first-class dependency type. Users can now track and update Docker images in Dockerfiles, Containerfiles, and Kubernetes YAML files. The update checker handles tag and digest updates, respects cooldowns, and validates image metadata via OCI annotations. This enables Dependabot to propose updates for container images alongside other package managers.

docker/lib/dependabot/docker · high confidence

Extracted shared file handling logic for Docker, Kubernetes, and Helm manifests

The \docker/lib/dependabot/shared\ directory now contains new, fully typed base classes (\SharedFileFetcher\, \SharedFileParser\, \SharedFileUpdater\) that encapsulate common logic for fetching, parsing, and updating Dockerfiles and YAML-based manifests (Kubernetes, Helm, Docker Compose). These shared components handle tasks like stripping BOMs from YAML, validating encoding, and managing image/digest updates, providing a reusable foundation for the Docker ecosystem's file operations.

docker/lib/dependabot/shared · high confidence

Go modules ecosystem restructured into a dedicated directory with native helpers

The Go modules ecosystem code has been reorganized into a dedicated \go\_modules/\ directory, separating it from the common shared code. This change introduces a new native helper binary built from Go source code (\go\_modules/helpers/\) to handle specific operations like resolving VCS remotes and normalizing Azure DevOps URLs. The directory now includes its own \Dockerfile\ for building the native helper, a \.bundle/config\ for Ruby dependencies, and a \.rubocop.yml\ for linting. The Ruby code in \go\_modules/lib/\ now registers the Go modules file fetcher, parser, and grapher, while the native helper provides a JSON-based interface for Go-specific tasks.

_go\modules · high confidence

Implement file updater for Devcontainers

Added a new \ConfigUpdater\ class in \devcontainers/lib/dependabot/devcontainers/file\_updater/config\_updater.rb\ to handle updating Devcontainer configuration files. This implementation enables Dependabot to automatically update Devcontainer dependencies by running the \devcontainer upgrade\ command and modifying the manifest and lockfile to reflect the new version or requirement.

_devcontainers/lib/dependabot/devcontainers/file\updater · high confidence

Initial implementation of Maven ecosystem support

This change introduces the complete Maven package manager implementation within the \maven\ directory. It includes the core components: \FileFetcher\ to retrieve \pom.xml\ and related files, \FileParser\ to extract dependencies, \PropertyValueFinder\ to resolve Maven properties, and \RepositoriesFinder\ to locate artifact repositories. The implementation also adds a \Dockerfile\ to build the Maven runtime environment, configuration files (\.bundle/config\, \.gitignore\, \.rubocop.yml\), and a \README.md\. This provides the foundational infrastructure for Dependabot to manage Maven-based Java projects.

maven · high confidence

Initial implementation of the Hex (Elixir) ecosystem support

This change introduces the complete implementation for the Hex package manager, enabling Dependabot to manage Elixir dependencies. It includes the core logic for fetching, parsing, and updating mix files and lockfiles, alongside native helper scripts for Elixir and Erlang (Elixir 1.19.5, Erlang 27, Hex 2.3.1). The addition allows the platform to detect, track, and propose updates for Elixir projects.

hex · high confidence

Initial support for the Julia ecosystem

Dependabot now supports updating dependencies in Julia projects. This includes parsing \Project.toml\ and \Manifest.toml\ files, resolving dependencies via Julia's Pkg manager, and fetching version information from the General registry. The implementation leverages a native Julia helper (\DependabotHelper.jl\) to handle complex versioning and compatibility logic, and includes support for Julia workspaces where multiple packages share a common manifest file.

bazel/lib/dependabot/bazel, julia · high confidence

Introduce 'silent' ecosystem for isolated integration testing

Added a new 'silent' package manager ecosystem designed for integration testing the updater code without making network calls. This minimal ecosystem uses local JSON files to list available versions, allowing tests to run in isolation. The change includes the core Ruby implementation files (file fetcher, parser, updater, metadata finder, etc.) and a comprehensive suite of Go-based end-to-end tests that validate update, security, and grouping behaviors.

silent · high confidence

Introduce .NET package correlation tooling for NuGet updates

The NuGet updater now includes a new \DotNetPackageCorrelation\ CLI tool and associated test suite. This tooling parses .NET Core release notes and markdown files to build a mapping of which SDK packages shipped with specific runtime packages. This enables the updater to more accurately determine compatible versions for transitive dependencies by correlating them with the .NET SDK version, improving the precision of update suggestions for .NET projects.

nuget/helpers · high confidence

Introduce Bundler 2 native helper implementation

Added new native helper files (bundler\_version\_constraint.rb, functions.rb) that implement the core logic for interacting with Bundler 2, including version constraint resolution, dependency sourcing, lockfile updating, and conflict detection. This provides the underlying functionality for the Bundler 2 support feature.

bundler/helpers/v2/lib · high confidence

Introduce DependencyGraphers base class and generic fallback for dependency graphing

Added a new \DependencyGraphers\ module with a \Base\ class and a \Generic\ fallback implementation to convert parsed dependencies into a structured graph for GitHub's Dependency Submission API. The \Base\ class introduces typed structures (\ResolvedDependency\, \ManifestGroup\, \ManifestGroupSnapshot\) and a \prepare!\ hook for ecosystem-specific graphing, while the \Generic\ class provides a default strategy that attributes dependencies to the right-most dependency file (typically the lockfile) and maps package managers to Package-URL (PURL) types. This establishes the foundation for ecosystem-specific graphers to inherit from, with the generic implementation ensuring existing functionality continues to work during the transition.

_common/lib/dependabot/dependency\graphers · high confidence

Introduce DependencySet to track multiple versions of dependencies

Added a new \DependencySet\ class that allows the system to track and combine multiple versions of the same dependency. This enables the tool to preserve all encountered versions of a dependency, merging their attributes (such as requirements and subdependency metadata) while maintaining insertion order. This change supports scenarios where a single dependency name maps to different versions across the project.

_common/lib/dependabot/file\parsers/base · high confidence

Introduce Elm JSON file updater for dependency updates

Added a new \ElmJsonUpdater\ class that handles updating \elm.json\ files by locating and replacing specific dependency version requirements within the JSON content. This enables the Dependabot system to automatically update Elm package versions in the project's dependency manifest.

_elm/lib/dependabot/elm/file\updater · high confidence

Introduce FileFetcher base class and documentation

Added a new \Dependabot::FileFetchers::Base\ class and a \README.md\ to the \common/lib/dependabot/file\_fetchers\ directory. The base class defines the core interface for fetching dependency files, including methods like \required\_files\_in?\, \required\_files\_message\, and \files\. It also includes logic for handling git submodules, retrying transient git clone errors, and managing repository contents paths. The documentation explains the public API and how to implement new file fetchers for different languages.

_common/lib/dependabot/file\fetchers · high confidence

Introduce Gradle ecosystem support

Added the Gradle ecosystem to Dependabot, enabling the detection, parsing, and updating of Gradle-based Java/Kotlin projects. This includes support for \build.gradle\ and \build.gradle.kts\ files, version catalogs (\libs.versions.toml\), Gradle wrapper updates, and included builds. The implementation provides file fetching, parsing, and updating capabilities for Gradle dependencies, plugins, and properties, along with a Dockerfile for the update environment.

gradle · high confidence

Introduce Julia language support via the new DependabotHelper.jl module

Add a new Julia helper module (DependabotHelper.jl) that enables Dependabot to manage Julia projects. The module provides functions to parse Project.toml and Manifest.toml files, discover package versions and metadata from registries, and handle custom registries. It supports Julia workspaces, batch operations for performance, and precompilation for faster startup. This adds the foundational capability to detect, parse, and update Julia dependencies.

julia/helpers/DependabotHelper.jl · high confidence

Introduce base FileUpdater classes for managing dependency and artifact file updates

Added a new \FileUpdaters::Base\ class that provides a shared foundation for language-specific file updaters, including common methods for checking file changes and updating dependencies. Introduced \FileUpdaters::ArtifactUpdater\ to handle arbitrary modified files within a git directory, supporting create, update, and delete operations with proper encoding and binary file detection. Added \FileUpdaters::VendorUpdater\ as a specialization of \ArtifactUpdater\ that automatically flags files as vendored, ensuring correct handling during grouped updates. These changes enable Dependabot to more robustly manage dependency files and supplementary artifacts across different ecosystems.

_common/lib/dependabot/file\updaters · high confidence

Introduce generic package version-finding and release-cooldown logic

Added new classes to the common library to support a generic package version finder and release cooldown filtering. The new \PackageDetails\ and \PackageRelease\ models store metadata about a package, including its available versions, distribution tags, and release details. The \PackageLatestVersionFinder\ abstract class provides a unified interface for finding the latest version, tag, and release, while applying filters for yanked versions, ignored versions, and security advisories. A new \ReleaseCooldownOptions\ class and associated filtering logic allow the system to temporarily suppress updates based on configurable cooldown periods, with a fallback to the current version if all releases are filtered out.

common/lib/dependabot/package · high confidence

Introduce native Composer v2 helper for PHP dependency updates

Added a new native helper for Composer v2, located in the composer/helpers/v2 directory. This includes a build script that copies and installs the helper, a PHP entry point (bin/run) that routes update, version-check, and hashing requests, and configuration files for PHP-CS-Fixer and PHPStan. This change enables the system to use a dedicated, native binary for handling Composer v2 ecosystem updates, rather than relying on the previous method.

composer/helpers · high confidence

Introduce native NuGet updater with .NET SDK installation

The NuGet ecosystem now utilizes a native updater tool built with .NET 10, replacing the previous Ruby-based implementation. This change introduces a new \NuGetUpdater\ CLI that handles file cloning, SDK installation from \global.json\ files, and dependency graph generation. The update process now automatically installs required .NET SDKs and targeting packs based on repository configuration, improving performance and reliability for .NET projects.

nuget · high confidence

Introduce new Bundler 2 native helper functions

Added new native helper classes for the Bundler 2 integration: \ConflictingDependencyResolver\ to identify dependency conflicts, \DependencySource\ to determine gem sources, \FileParser\ to parse lockfiles and gemfiles, \ForceUpdater\ to force-update dependencies, \LockfileUpdater\ to regenerate lockfiles, and \VersionResolver\ to resolve latest versions. These files implement the core logic for managing Ruby dependencies using the Bundler 2 API.

bundler/helpers/v2/lib/functions · high confidence

Introduce new development and release scripts

The \bin\ directory now includes several new executable scripts to streamline development workflows. \bin/dry-run.rb\ allows developers to simulate an update run for a given repository without creating a pull request, supporting a wide range of package managers. \bin/test\ provides a convenient way to run tests within the Docker development shell for a specific ecosystem. \bin/docker-dev-shell\ manages the Docker-based development environment, building per-ecosystem images and handling container lifecycle. \bin/ci-test\ simulates the CI process for a given suite. \bin/bump-version.rb\ automates the process of updating version numbers in the project's Gemfile.lock and common library. Additionally, \bin/lint\ and \bin/rubocop\ are added to run shellcheck and RuboCop respectively, ensuring code quality.

bin · high confidence

Introduce standalone \`dependabot-terraform\` ecosystem package

The Terraform ecosystem is now a standalone package (\terraform/\) with its own \Gemfile\, Dockerfile, and helper build scripts, separating it from the core monorepo structure. This includes the full implementation of the Terraform file fetcher, parser, updater, and metadata finder, along with a native helper script to download and verify the \hcl2json\ binary. The package registers itself with the central \FileFetchers\, \FileParsers\, and \FileUpdaters\ registries, enabling Dependabot to detect, parse, and update Terraform configurations and provider dependencies.

terraform · high confidence

Introduce support for the Python \`uv\` package manager

Added a new \uv\ ecosystem to Dependabot, enabling the detection, parsing, and updating of \uv.lock\ and \pyproject.toml\ files. This includes a dedicated file fetcher to retrieve workspace members and metadata, a parser to extract dependencies from TOML and lockfiles, and a dependency grapher that builds the dependency tree from \uv.lock\. The implementation also provisions Python versions (3.10–3.14) and the \uv\ binary in the updater's Docker environment.

uv · high confidence

Introduce typed base class for file parsers

The \Dependabot::FileParsers::Base\ class is introduced as a strongly typed, abstract base for all language-specific file parsers. It enforces a consistent interface for parsing dependencies, managing credentials, and handling repository context. This change provides a standardized foundation for implementing new parsers and ensures type safety across the file parsing layer.

_common/lib/dependabot/file\parsers · high confidence

Introduce v2 native helper for Bundler 2 support

Added a new v2 native helper tree for Bundler 2, including a build script that installs the requested Bundler version and a run.rb entry point that activates Bundler 2 with version constraints and applies necessary monkey patches. This isolates Bundler 2 functionality from other helper versions.

bundler/helpers/v2 · high confidence

Native conda update checking and requirement updating

Users with conda dependencies now have native support for version updates. A new \LatestVersionFinder\ resolves the latest available versions by querying the Conda registry (with fallback to pip for compatible packages), and a \RequirementsUpdater\ modifies \environment.yml\ files to reflect new versions according to the configured update strategy (e.g., widening ranges or bumping versions). A \RequirementTranslator\ converts conda-style version constraints into pip-compatible formats where necessary.

_conda/lib/dependabot/conda/update\checker · high confidence

New API clients for Azure, Bitbucket, CodeCommit, and GitHub releases

Added new API client implementations for Azure DevOps, Bitbucket, AWS CodeCommit, and GitHub releases, each with Sorbet strict typing and retry logic where applicable. These clients provide the underlying HTTP interactions for their respective version control systems, enabling Dependabot to fetch repository contents, commit hashes, and pull request data from these platforms.

common/lib/dependabot/clients · high confidence

New Composer v2 helper classes for dependency updates

Added new helper classes in the Composer v2 integration to manage plugin registration, error handling, and update operations. The \DependabotPluginManager\ overrides package registration to safely ignore PHP\_CodeSniffer setup errors during lockfile-only installs. The \ExceptionIO\ class captures and throws runtime exceptions for specific Composer resolution errors. The \Updater\ and \UpdateChecker\ classes implement the core logic for running Composer update operations, handling credentials, and retrieving the latest resolvable versions of dependencies.

composer/helpers/v2 · high confidence

New rake tasks to scaffold and update ecosystem boilerplate

Developers can now use \rake ecosystem:scaffold\, \rake ecosystem:update\_infrastructure\, and \rake ecosystem:create\ to automatically generate the directory structure, template files, and supporting infrastructure for a new ecosystem. The \ecosystem:scaffold\ task creates the initial boilerplate, while \update\_infrastructure\ updates CI workflows, gemspecs, and other configuration files to include the new ecosystem.

rakelib · high confidence

New versioning and wildcard matching utilities

The common library now includes a \Dependabot::Version\ constant set to 0.390.0, and introduces a new \WildcardMatcher\ class that provides a typed method for matching strings against wildcard patterns (e.g., \\*\), supporting both Ruby and Sorbet type annotations.

common/lib · high confidence

Register Bundler as a supported package manager

The Bundler package manager is now registered within the application, enabling the system to fetch, parse, and update Ruby dependencies managed by Bundler. This includes loading the necessary modules for file handling, versioning, and update checking, as well as configuring production dependency detection for the 'bundler' ecosystem.

bundler/lib/dependabot, composer/lib/dependabot · high confidence

Rust/Cargo ecosystem implementation

Added support for the Rust/Cargo ecosystem, enabling Dependabot to fetch, parse, and update Cargo.toml and Cargo.lock files. This includes handling workspace dependencies, path dependencies, and custom registries, as well as stripping credential-provider settings from .cargo/config.toml to ensure secure authentication via environment variables.

cargo/lib/dependabot/cargo · high confidence

Standardize project configuration and development environment

The repository introduces a suite of new configuration files to standardize code style, formatting, and development workflows. A \.editorconfig\ enforces consistent indentation, line endings, and character encoding across editors. A \.rubocop.yml\ file configures the RuboCop linter with specific rules for Ruby, RSpec, and Sorbet, including enabling new cops and setting a target Ruby version of 3.3. A \.codespellrc\ file configures the codespell tool to ignore specific technical terms and file types. Additionally, \.gitignore\ and \.dockerignore\ files are added to exclude build artifacts, environment files, and IDE-specific directories from version control and Docker builds. The \.gitattributes\ file ensures consistent line endings and file type detection, while \.git-blame-ignore-revs\ tracks commits to ignore in git blame for style changes. Finally, \.gitmodules\ is added to manage the NuGet.Client and dotnet-core submodules.

(repo-wide) · high confidence

Support for building path dependencies from lockfile data

A new PathDependencyBuilder class has been added to the Composer file fetcher. This component is responsible for constructing path dependencies by extracting their content from the lockfile. If a path dependency cannot be built, the system currently returns nil, which may result in errors in the UpdateChecker or FileUpdater. The implementation includes strict typing for the lockfile parsing and content building logic.

_composer/lib/dependabot/composer/file\fetcher · high confidence

Architecture

Extracted changelog, commits, and release finding logic into shared base classes

Moved the \ChangelogFinder\, \ChangelogPruner\, \CommitsFinder\, and \ReleaseFinder\ classes into the \common/lib/dependabot/metadata\_finders/base\ directory. This refactoring consolidates metadata-finding logic into shared base classes, allowing different package managers to inherit or reuse these implementations rather than each maintaining their own version of these finders.

_common/lib/dependabot/metadata\finders/base · high confidence

Python helpers refactored into modular lib files

The Python helper scripts have been refactored into a structured library under python/helpers/lib, splitting functionality into separate modules for hashing (hasher.py), parsing (parser.py), and a package init file. This reorganization improves code maintainability and separation of concerns within the Python ecosystem support.

python/helpers · high confidence

Refactor Cargo file updating into dedicated updater classes

The Cargo file update logic has been refactored into three new classes: \LockfileUpdater\, \ManifestUpdater\, and \WorkspaceManifestUpdater\. This change separates the concerns of updating \Cargo.lock\, individual \Cargo.toml\ manifests, and workspace-level dependency declarations, making the codebase more modular and easier to maintain.

_cargo/lib/dependabot/cargo/file\updater · high confidence

Refactored Cargo update checking into dedicated classes

The Cargo update checker logic has been restructured into four new classes: FilePreparer, LatestVersionFinder, RequirementsUpdater, and VersionResolver. This refactoring separates concerns for preparing dependency files, finding the latest resolvable version, updating requirements, and resolving versions, improving code maintainability and type safety through Sorbet strict typing.

_cargo/lib/dependabot/cargo/update\checker · high confidence

Reorganize and retype the Bundler ecosystem implementation

The Bundler package manager implementation has been reorganized into a new directory structure (bundler/lib/dependabot/bundler) with all classes strictly typed using Sorbet. This includes new or refactored components such as CachedLockfileParser, FileFetcher, FileParser, FileUpdater, Helpers, Language, MetadataFinder, NativeHelpers, PackageManager, Requirement, UpdateChecker, and Version. The reorganization groups related logic for parsing, fetching, updating, and checking updates for Ruby/Bundler projects, improving code maintainability and type safety.

bundler/lib/dependabot/bundler · high confidence

Behavioural changes

Add immutable Git credential helper script

A new executable script, common/bin/git-credential-store-immutable, has been added to the repository. This Ruby script acts as a wrapper for the Git credential-store, restricting operations to the 'get' command only. By preventing 'store' and 'erase' commands from mutating the credential store, it enforces an immutable approach to credential management, ensuring that credentials cannot be written or deleted through this helper.

common/bin · high confidence

Bazel tooling now uses a shared Gemfile for dependency updates

A new configuration file has been added to the Bazel directory to point to a shared Gemfile located in the dependabot-updater directory. This change aligns the Bazel environment with the project's centralized dependency update strategy, ensuring that Bazel's Ruby dependencies are managed consistently with the rest of the codebase.

bazel/.bundle · high confidence

Centralized update-checker base class and shared filtering logic

The \common/lib/dependabot/update\_checkers\ directory now provides a shared \Base\ class and supporting modules (\CooldownCalculation\, \VersionFilters\) that all language-specific update checkers inherit from. This refactor consolidates common update-checking logic—including version filtering against security advisories, cooldown window calculations, and requirement update strategies—into the common library, allowing ecosystem-specific checkers to focus on their unique resolution logic while reusing shared behavior.

_common/lib/dependabot/update\checkers · high confidence

Configure Bundler to use the project's Gemfile

A new Bundler configuration file has been added to the devcontainers directory, setting BUNDLE\_GEMFILE to point to the Gemfile located in the ../dependabot-updater directory. This ensures that Bundler uses the correct dependency definitions when running in the devcontainer environment.

devcontainers/.bundle · high confidence

Configure Conda to use a specific Gemfile for dependency updates

A new configuration file at conda/.bundle/config has been added to specify the Bundler gemfile path as '../dependabot-updater/Gemfile'. This change directs the Conda environment's bundle operations to use the Gemfile located in the dependabot-updater directory, ensuring consistent dependency management for that specific context.

conda/.bundle · high confidence

Consolidate Docker and Docker Compose module registrations

The Docker and Docker Compose package managers are now registered via consolidated top-level entry points (docker.rb and docker\_compose.rb) that require their respective file fetchers, parsers, and updaters. Both modules are configured with 'strong' type checking, register their label details for pull request creation, and register production checks. This change ensures that the version, requirement, and metadata finder classes are correctly associated with their respective package managers.

docker/lib/dependabot · medium confidence

Devcontainers: Add cooldown filtering to version updates

The devcontainers update checker now applies a cooldown period to new releases. The new LatestVersionFinder filters out versions that are too recent, using a configurable cooldown window to prevent immediate updates. This ensures that only releases outside the cooldown period are considered for updates.

_devcontainers/lib/dependabot/devcontainers/update\checker · high confidence

Extracted dependency source logic into a dedicated class

The logic for determining a dependency's source type and fetching version information has been extracted from the main LatestVersionFinder into a new DependencySource class. This refactoring improves code organization and allows for more precise handling of different dependency sources (RubyGems, private registries, Git) with dedicated methods for each.

_bundler/lib/dependabot/bundler/update\_checker/latest\_version\finder · high confidence

Improved PR message formatting and sanitization

Pull request messages now feature more robust sanitization of links and mentions, including stricter handling of GitHub references, team mentions, and code blocks to prevent accidental notifications or broken links. The message builder has been refactored to extract title composition into a dedicated TitleBuilder, issue linking into an IssueLinker, and metadata presentation into a MetadataPresenter, resulting in cleaner, more maintainable code. Additionally, the system now supports zero-width spaces in @mentions to prevent accidental notifications while preserving text formatting.

_common/lib/dependabot/pull\_request\_creator/message\builder · high confidence

Improved error handling and stability for npm, Yarn, and pnpm

The npm\_and\_yarn ecosystem received a comprehensive set of fixes and improvements to handle various edge cases and errors more gracefully. This includes adding exception handling for override failures, registry auth failures, and Yarn-specific errors (such as YN0035 and YN0082). The update also addresses issues with empty package manager names, invalid package names, and malformed lockfiles. Additionally, it fixes bugs related to peer dependency conflicts, sub-dependency updates, and private registry configurations, ensuring that the tooling is more robust against network issues, invalid data, and configuration errors.

_npm\_and\yarn · high confidence

Improved error handling and type safety in common library

The common library received a significant overhaul to improve reliability and maintainability. Key changes include the introduction of a \SecurityAdvisory\ class to determine if a version is vulnerable, and the addition of a \Dependency\#direct?\ method to distinguish direct from transitive dependencies. Error handling was enhanced by adding specific error classes like \AllVersionsIgnored\ and \DependencyFileNotParseable\, and by sanitizing credentials in error messages. The codebase also saw a major push for strict typing (Sorbet), replacing \T.untyped\ with specific types across 16+ files, and removing \OpenStruct\ usage. Additionally, the \GitCommitChecker\ was strictly typed, and the \Dependency\ class was moved to the common library to share logic across ecosystems.

common/lib/dependabot · high confidence

Introduce shared metadata finder base class and public API

Adds a new \Dependabot::MetadataFinders::Base\ class that provides a unified interface for retrieving dependency metadata. This base class implements methods for \source\_url\, \homepage\_url\, \changelog\_url\, \changelog\_text\, \upgrade\_guide\_url\, \upgrade\_guide\_text\, \releases\_url\, \releases\_text\, \commits\_url\, and \commits\. It also includes stub methods for \maintainer\_changes\, \install\_script\_changes\, and \attestation\_changes\ to support future behavioral changes. The change includes a \README.md\ documenting the public API and usage for language-specific implementations.

_common/lib/dependabot/metadata\finders · high confidence

Introduces a typed base interface for requirements updaters

Adds a new \base.rb\ file that defines a typed base interface for requirements updaters using Sorbet. This interface enforces the implementation of \updated\_requirements\, \version\_class\, and \requirement\_class\ methods, ensuring that all concrete updater classes adhere to a consistent contract for handling dependency versions and requirements.

_common/lib/dependabot/requirements\updater · medium confidence

Python ecosystem receives numerous bug fixes and stability improvements

The Python ecosystem received a large number of bug fixes and stability improvements. Key changes include fixing Python version defaulting to 3.9 (lowest available) instead of latest when no explicit version is specified, handling wildcards in requirements with non-equality operators, and improving error handling for unreachable git dependencies. Additional fixes address issues with Poetry sub-dependencies, PEP 621 projects, and pip-compile file updates. The changes also include better handling of environment variables, markers, and private registry sources.

python · medium confidence

Refactor Bundler file parsing with Prism and Sorbet

The Bundler file parser has been refactored to use the Prism AST parser instead of the previous parser, improving how Gemfile and gemspec files are processed. This change introduces new classes—FilePreparer, GemfileDeclarationFinder, and GemspecDeclarationFinder—to handle dependency declaration detection. The implementation adds Sorbet type annotations (typed: strong/strict) and leverages Prism for more robust parsing of Ruby code, which should lead to more accurate dependency detection and better handling of complex Gemfile structures.

_bundler/lib/dependabot/bundler/file\parser · high confidence

Refactor Bundler file update logic into dedicated updater classes

The Bundler file update logic has been refactored into dedicated classes for each file type: \GemfileUpdater\, \GemspecUpdater\, \LockfileUpdater\, \RequirementReplacer\, \GitPinReplacer\, \GitSourceRemover\, \GemspecSanitizer\, \GemspecDependencyNameFinder\, and \RubyRequirementSetter\. This change replaces the previous monolithic \FileUpdater\ implementation with specialized components that handle specific update operations, such as replacing version requirements, updating git pins, removing git sources, sanitizing gemspecs, and setting Ruby version requirements.

_bundler/lib/dependabot/bundler/file\_updater, composer/lib/dependabot/composer/file\updater · high confidence

Refactor Composer update checking into dedicated finder and updater classes

The Composer update checking logic has been refactored to improve maintainability and type safety. A new \LatestVersionFinder\ class now encapsulates the logic for determining the latest available version, while a new \RequirementsUpdater\ class handles the transformation of version constraints. The \VersionResolver\ has been updated to use these new classes, introducing stricter typing and better error handling for Composer-specific scenarios like missing PHP extensions and unreachable VCS sources.

_composer/lib/dependabot/composer/update\checker · high confidence

Refactor Hex helper scripts to use structured JSON output and stderr logging

The Hex helper scripts (check\_update, do\_update, parse\_deps, and run) have been rewritten to output structured JSON via stderr instead of raw stdout, and to handle errors and timeouts more robustly. This change improves how dependency updates and checks are reported to the caller, ensuring that log messages do not interfere with the machine-readable output. The \run.exs\ script now decodes and validates JSON responses, while the other scripts use \:logger\ to send logs to stderr, keeping stdout clean for structured data.

hex/helpers · high confidence

Refactor branch naming strategy for improved clarity and maintainability

The branch naming logic has been refactored into a new \Base\ class that centralizes sanitization, word separation, case transformation, and length limiting. Specific strategies (\SoloStrategy\, \DependencyGroupStrategy\, \MultiEcosystemStrategy\) now inherit from this base, each implementing their own \new\_branch\_name\ logic. This change introduces support for configurable \word\_separator\, \branch\_name\_case\, and \template\ parameters, allowing for more flexible and consistent branch name generation across different update types.

_common/lib/dependabot/pull\_request\_creator/branch\namer · high confidence

Refactored Bazel file fetching into specialized fetcher classes

The Bazel file fetching logic has been refactored into distinct, specialized classes to improve maintainability and clarity. A new \PathConverter\ utility handles Bazel label-to-path conversion. New fetchers include \BzlFileFetcher\ for handling \.bzl\ files and their \load()\ dependencies, \IncludeExtractor\ for processing \include()\ statements in \MODULE.bazel\ files, \ModulePathExtractor\ for parsing attributes like \lock\_file\ and \local\_path\_override\, \DirectoryTreeFetcher\ for recursive directory traversal, and \DownloaderConfigFetcher\ for \.bazelrc\ configurations. This change reorganizes the existing \FileFetcher\ responsibilities into these focused components.

_bazel/lib/dependabot/bazel/file\fetcher · high confidence

Refactored Bundler update checker into specialized sub-components

The Bundler update checker logic has been refactored into distinct, specialized classes to improve maintainability and type safety. The \UpdateChecker\ class now delegates to \FilePreparer\ for managing dependency files, \LatestVersionFinder\ for identifying candidate versions, \VersionResolver\ for resolving the final version, \RequirementsUpdater\ for updating version constraints, \ForceUpdater\ for forced updates, \CooldownOptionsBuilder\ for handling release cooldowns, and \ConflictingDependencyResolver\ for identifying blocking dependencies. These components are now fully typed with Sorbet and structured to handle specific parts of the update check process.

_bundler/lib/dependabot/bundler/update\checker · high confidence

Refactored Elm update checker with strict typing and new CLI parser

The Elm update checker has been refactored to improve type safety and parsing logic. A new \CliParser\ class was added to handle parsing of install and upgrade preview text from the Elm CLI, extracting dependency names and versions. The \LatestVersionFinder\ and \Elm19LatestVersionFinder\ classes were updated with Sorbet strict typing, including explicit type signatures for all methods and attributes. Additionally, a \RequirementsUpdater\ class was introduced to manage the transformation of version requirements during updates, supporting range and exact version updates. These changes enhance the reliability and maintainability of the Elm ecosystem's update checking process.

_elm/lib/dependabot/elm/update\checker · high confidence

Refactored build and test scripts for ecosystem modularity

The repository's build and testing infrastructure has been restructured to support independent ecosystem containers. A new \script/\_common\ library provides shared functions for Docker image building, tag mapping, and cache configuration, which are now used by \script/build\ and \script/ci-test-updater\. The \script/dependabot\ script has been updated to mount all ecosystem directories (including new ones like \uv\, \vcpkg\, and \opentofu\) into the CLI container. Additionally, a \script/sorbet-untyped-ratchet\ script was added to enforce a burndown of \T.untyped\ usage in the codebase, and \script/test-rakefile\ was introduced to verify the modularized Rakefile structure.

script · high confidence

Refactored workspace management into a modular, type-safe structure

The workspace implementation has been refactored into separate, specialized classes: a \Base\ abstract class and a \Git\ concrete implementation, along with a new \ChangeAttempt\ class to track success and failure states. This change introduces strict Sorbet typing (\\# typed: strong/strict\) to the workspace module, improving code maintainability and error handling. Users benefit from more robust handling of git operations, including explicit change storage and better debugging of failed attempts.

common/lib/dependabot/workspace · high confidence

Removed Ruby dependency parsing and Dependency class

The Ruby file parser and the Dependency class have been removed from the codebase. This eliminates the ability to parse Ruby/Gemfile dependencies, as the parser relied on the now-removed Dependency class to represent parsed results.

lib/bumper · high confidence

Replace Ruby parser with Prism for Bundler file fetching

The Bundler file fetcher now uses the Prism parser to locate and resolve dependencies, including \eval\_gemfile\, \gemspec\, and \path\ declarations. This change removes all calls to \eval\ during file fetching, which improves security by avoiding the execution of arbitrary code, and provides more robust parsing of Gemfile structures.

_bundler/lib/dependabot/bundler/file\fetcher · high confidence

Standardize Bundler configuration across multiple language packages

The Bundler configuration file (.bundle/config) is added to the bundler, cargo, common, composer, docker, and elm directories. Each file sets BUNDLE\_GEMFILE to point to the shared Gemfile in the dependabot-updater directory, ensuring consistent dependency resolution and test behavior across these components.

(repo-wide) · high confidence

Strictly typed Dependabot config file parsing

The \Dependabot::Config::File\ and \FileFetcher\ classes have been refactored to use Sorbet's strong typing, ensuring that the \dependabot.yml\ configuration file is parsed into strongly-typed objects (\UpdateConfig\, \IgnoreCondition\, \CommitMessageOptions\). This change enforces data integrity for update configurations, including support for \exclude-paths\, \commit-message\ options, and \ignore\ conditions with \update-types\ and \dependency-name\ filters. The \FileFetcher\ now strictly validates the presence of the configuration file, and the \IgnoreCondition\ logic now correctly handles nil versions and transforms update types for version matching.

common/lib/dependabot/config · high confidence

Updated Sorbet type definitions for updated gems

The Sorbet RBI files for several gems have been regenerated to reflect the latest upstream changes. This includes updated type signatures for \faraday\, \rainbow\, \webmock\, \addressable\, \ast\, \aws-eventstream\, \aws-partitions\, \aws-sdk-codecommit\, \aws-sdk-core\, \aws-sdk-ecr\, and \aws-sigv4\. These updates ensure that the static type checker has the most current interface definitions for these dependencies.

sorbet · high confidence

Updater refactors and type safety improvements

The updater has been refactored to use a new \Dependabot::Updater::Operations\ structure, replacing the previous monolithic \Updater.run\ flow with distinct operation classes for tasks like \UpdateAllVersions\ and \RefreshSecurityUpdatePullRequest\. This change improves code organization and testability. Additionally, the codebase has been migrated from \sentry-raven\ to \sentry-ruby\ for error reporting, and significant progress has been made on Sorbet type strictness, with many files now passing at the \typed: strong\ level. The \DependencyGroupEngine\ has been introduced to handle dependency grouping logic, and the \Job\ class has been typed to use structured objects instead of raw hashes.

updater · high confidence

Test coverage

1 commit adding/updating tests in composer/spec/fixtures/git; 2 commits adding/updating tests in cargo/spec/fixtures/git; Add docker-compose fixture files for parser tests; Add dummy package manager test fixtures; Add test fixture for git tag versioning; Add tests for PR message builder components; Add tests for PathDependencyBuilder; Add tests for class registration in Docker and Docker Compose; Added Azure test fixtures for Git operations; Added Bitbucket fixture data for pull request and repository tests; Added Dockerfile fixtures for Docker image parsing tests; Added ECR response fixtures for authentication and error scenarios; Added Elm fixture files for dependency resolution tests; Added Elm spec helper for shared test utilities; Added Ruby gemspec and RubyGems API response fixtures; Added \_\init\\_.py for my-project package; Added changelog fixtures for jsdom, Rails 5.2, and Sentry; Added comprehensive test coverage for Bazel ecosystem support; Added comprehensive test coverage for Cargo file updaters; Added comprehensive test coverage for Cargo update checker components; Added comprehensive test coverage for Composer ecosystem components; Added comprehensive test coverage for the file fetcher base class and shared examples; Added comprehensive tests for Bundler file updater components; Added empty Rust source file for version conflict test fixture; Added initial conda test infrastructure; Added spec helper for Composer tests; Added specs for Composer lockfile and manifest updaters; Added test coverage for Azure, GitHub, and GitLab pull request updaters; Added test coverage for Bundler file parsing components; Added test coverage for Bundler v2 helper functions and patches; Added test coverage for Bundler v2 native helper functions; Added test coverage for core Dependabot models and utilities; Added test coverage for multiple client implementations; Added test coverage for the devcontainers ecosystem; Added test coverage for the dry-run script; Added test fixture for Rust toolchain configuration; Added test fixture for binary file handling; Added test fixture for git upload pack protocol; Added test fixtures for CodeCommit client; Added test fixtures for Julia workspace sub-packages; Added test fixtures for command execution scenarios; Added test fixtures for local path module resolution; Added test fixtures for nested Terraform modules; Added test fixtures for the Bun ecosystem; Added test helper infrastructure for Bundler specs; Added test helper scripts for simulating subprocess errors; Added test infrastructure for Bun ecosystem; Added test infrastructure for the dotnet\_sdk spec; Added test package for Julia helper; Added tests for Bundler ecosystem helpers and spec files; Added tests for Bundler file fetcher components; Added tests for Bundler package details fetching; Added tests for Composer dependency management; Added tests for Dependabot config file fetching and ignore condition logic; Added tests for Docker Compose file handling; Added tests for Docker registry credential resolution; Added tests for Elm package details fetcher; Added tests for GitCommitChecker::SourceDetails; Added tests for PullRequestCreator components; Added tests for branch naming strategies; Added tests for changelog, commits, and release finders; Added tests for class registration in Bundler, Cargo, and Elm; Added tests for package release and cooldown configuration; Added tests for the Bundler dependency source update checker; Added tests for the DependencySet class; Added tests for the Elm ecosystem support; Added tests for the Git workspace utility; Added tests for the common metadata finders base class and shared examples; Added tests for the dotnet\_sdk ecosystem; Added tests for update checker base class, cooldown calculation, and version filtering; Added unit tests for file updater components; Expanded Cargo fixture coverage for manifest edge cases; Expanded test coverage for Cargo ecosystem; Expanded test coverage for Docker ecosystem components; Introduce CI test script for Composer; Introduce automated CI test script for Bundler; Removed obsolete test files and dependencies; Standardized CI test execution across ecosystems; Standardized test environment with coverage and profiling support; Updated Cargo lockfile test fixtures; Updated Ruby gem fixture data for testing; Updated RubyGems API response fixtures for testing.

Dependencies

Routine dependency updates across all helper directories

This update refreshes the dependencies in the /npm\_and\_yarn/helpers, /python/helpers, /composer/helpers/v2, /go\_modules/helpers, and /updater directories. The changes include routine version bumps for various packages such as eslint, jest, npm, and pip-tools, ensuring that the helper tools remain up to date with the latest stable releases.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 45.

Lenses

  • Code Health 69
  • Architecture 95
  • Maturity 69
  • Readiness 36
  • Security 33

Changes since last survey

  • 300 commits — 270 feature/other, 30 fixes

By area

  • updater/lib — 43 commits
  • common/lib — 34 commits
  • npm_and_yarn/helpers — 32 commits
  • bun/helpers — 17 commits
  • (root) — 14 commits
  • python/lib — 12 commits
  • npm_and_yarn/lib — 10 commits
  • nuget/helpers — 10 commits
  • maven/lib — 6 commits
  • python/helpers — 6 commits
  • cargo/lib — 5 commits
  • docker/lib — 5 commits
  • npm_and_yarn/spec — 5 commits
  • updater/spec — 5 commits
  • vcpkg/lib — 5 commits
  • cargo/spec — 4 commits
  • github_actions/lib — 4 commits
  • gradle/Dockerfile — 4 commits
  • pre_commit/lib — 4 commits
  • uv/Dockerfile — 4 commits

Notable commits

  • fix: Add uv grapher regression test for versionless back-references (#15259) (#15778)
  • fix: Address review feedback on vcpkg version comparison and fix resolution
  • fix: Compute npm audit fix tree on a fresh Arborist instance (#15514)
  • fix: Draft fix for path dependency not reachable
  • fix: Fix Docker cooldown not respected for multi-arch images missing Last-Modified (#15486)
  • fix: Fix Gradle lockfile updates for repos with in-repo convention plugins (#15677)
  • fix: Fix RuboCop offenses
  • fix: Fix UV DependencyGrapher to detect nested uv.lock in monorepos (#15520)
  • fix: Fix codespell typo in updater job spec (#15599)
  • fix: Fix gemspec infrastructure updates
  • fix: Fix npm ignoring scoped registry issue (#15692)
  • fix: Fix pnpm 11 peer dependency checks
  • fix: Fix security update jobs failing with dependency_file_not_found for single-directory manifests (#15658)
  • fix: Fix some comments that still refer to degraded
  • fix: Fix type boundaries in Gradle, Swift, and pre_commit
  • fix: Fix typed source validation
  • fix: Merge branch 'main' into fix-actions-cooldown-precision-regression
  • fix: Merge pull request #15746 from theinfosecguy/fix-dotnet-sdk-preview-version
  • fix: Merge pull request #15760 from dependabot/fix-actions-cooldown-precision-regression
  • fix: Respect resolutions/overrides and pin Berry wildcard updates to fix spurious NoChangeError (#15701)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

dependabot/dependabot-core was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 7 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 2ef9fd2f47263a5fa2bc305b129d3c9e88d2a831 — the exact code this score is about.
  • Scored under rubric-2026.08.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using localhost:5005/codehealth-analyzer rubric-2026.08.15.