dependabot/dependabot-core
44.6
Weak · 7 August 2026
152.8k
lines of production code
3
measurements over time
What this system is
This release delivers extensive new ecosystem support for Bun, Julia, Conda, OpenTofu, Dev Containers, and Swift, while introducing native helpers for Go, NuGet, and Python's uv. A major architectural shift involves refactoring core libraries—Bundler, Cargo, and Composer—into modular, strictly typed components to improve maintainability and type safety. Additionally, the system now supports private registries for Docker images, Git submodules, and Azure/Bitbucket/CodeCommit platforms, alongside significant improvements to error handling and CI testing infrastructure.
Features
Add Bun lockfile and package.json update support
Introduces new classes to handle Bun dependency updates: \BunLockfileUpdater\ orchestrates the update process by generating \.npmrc\ configuration and executing \bun install\ commands; \NpmrcBuilder\ constructs the \.npmrc\ file from registry credentials and lockfile data; \PackageJsonPreparer\ sanitizes \package.json\ content by converting SSH git sources to HTTPS and removing invalid characters; and \PackageJsonUpdater\ applies version changes to \package.json\ and its \resolutions\ section. These changes enable Dependabot to manage Bun-based projects by updating lockfiles and package manifests.
_bun/lib/dependabot/bun/file\updater · high confidence
Add Bun lockfile parsing support
Introduces new parsers for the Bun package manager, enabling Dependabot to read \bun.lock\ lockfiles and extract dependency metadata. The implementation includes \BunLock\ for parsing the lockfile content and \LockfileParser\ to orchestrate the extraction, allowing the system to track Bun dependencies alongside existing npm/yarn support.
_bun/lib/dependabot/bun/file\parser · high confidence
Add Bundler PackageDetailsFetcher for private registry support
A new \PackageDetailsFetcher\ class has been introduced for the Bundler package manager, enabling the system to fetch package version details from private registries. The implementation includes robust error handling for invalid JSON responses and ensures that dependencies sourced from 'git' or 'other' return \nil\ rather than attempting to query RubyGems. This change supports private registry cooldown functionality and improves error reporting for failed fetches.
bundler/lib/dependabot/bundler/package · medium confidence
Add Composer package details fetcher
A new \PackageDetailsFetcher\ class has been introduced for the Composer package manager. This component is responsible for retrieving and parsing package metadata and release information from various registries, including support for both v1 and v2 API formats. It handles credential-based authentication for private registries and manages the logic for fetching version details, which is essential for accurate dependency updates.
bun/lib/dependabot/bun/package, cargo/lib/dependabot/cargo/package, composer/lib/dependabot/composer/package · high confidence
Add GitHub Actions ecosystem support with lockfile integration
Introduces a new \github\_actions\ ecosystem to detect, update, and manage GitHub Actions dependencies. This includes a file fetcher and parser that identify actions in workflow YAML files, an update checker that resolves versions via git tags, and a file updater that rewrites workflow files with new refs. A key addition is the integration with the \gh-actions-lock\ tool to generate and maintain an \actions.lock\ lockfile, ensuring that updates respect the authoritative state of the repository's actions. The implementation includes a dedicated Dockerfile, configuration files, and Sorbet type annotations.
_github\actions · high confidence
Add Nix ecosystem support for updating flake.lock and channel tarball inputs
Users can now have Dependabot monitor and update Nix flake dependencies. This adds full support for Git-backed flake inputs (GitHub, GitLab, SourceHut, and generic Git), NixOS channel tarball inputs (with automatic revision resolution), and indirect registry shorthands. The update process runs \nix flake update\ to regenerate the lockfile, and the system correctly handles versioned branches, tag-based pins, and channel versioning with ignore filters.
nix · high confidence
Add OpenTofu ecosystem support
Introduces a new OpenTofu ecosystem to Dependabot, enabling the detection, parsing, and updating of OpenTofu configuration files (.tf, .tofu, .hcl) and Terragrunt files. The implementation includes a file fetcher to locate and filter relevant configuration files, a parser to extract dependencies from modules, providers, and local paths, and an updater to modify version constraints in the source files. It also supports OCI modules, Git-based modules, and registry-hosted modules, with metadata and version resolution logic integrated into the existing Dependabot pipeline.
(repo-wide) · high confidence
Add PullRequestUpdater implementations for Azure, GitHub, and GitLab
The \common/lib/dependabot/pull\_request\_updater\ directory now includes new \Azure\, \Github\, and \Gitlab\ classes that implement the \PullRequestUpdater\ interface. These classes handle updating pull requests by creating commits and updating branch references for their respective platforms, supporting features like author details, signature keys, and target project IDs.
_common/lib/dependabot/pull\_request\updater · high confidence
Add Rust/Cargo package manager support
Added the core implementation for the Rust/Cargo package manager, including file fetching, parsing, updating, and metadata finding. The new \cargo.rb\ file registers the Cargo file fetcher, parser, update checker, file updater, and metadata finder. It also registers the 'rust' label for pull requests and sets up a production check for Cargo dependencies.
cargo/lib/dependabot · high confidence
Add Swift ecosystem support for Dependabot
Introduces a new Swift package manager integration, enabling Dependabot to fetch, parse, and update Swift dependencies. The implementation supports both classic SPM projects (via Package.swift) and Xcode-managed SwiftPM projects (via Package.resolved and project.pbxproj files). It includes a FileFetcher to locate and retrieve dependency files, a FileParser to extract dependency metadata, and a FileUpdater to modify lockfiles and project files. The Dockerfile sets up the Swift 6.3.1 runtime, and the lib/ directory contains the core logic for parsing and updating Swift dependencies.
swift · high confidence
Add VS Code Remote Development on Docker devcontainer
The .devcontainer directory now contains the configuration files (Dockerfile, devcontainer.json, and shell scripts) required to run the project in a VS Code Remote Container. This provides a pre-configured development environment with Ubuntu, Ruby 4.0.5, .NET 8/9/10 SDKs, Node.js, Go, Rust, and relevant VS Code extensions, streamlining the setup process for new contributors and CI environments.
.devcontainer · high confidence
Add initial plumbing for the Dev Containers package manager
A new \devcontainers\ package manager is registered within the Dependabot library, including the file fetcher, parser, update checker, file updater, metadata finder, requirement, and version classes. The entry point registers the package manager with the pull request creator's labeler and configures the dependency production check to always return true, enabling Dependabot to process \devcontainers\ dependencies.
devcontainers/lib/dependabot · high confidence
Add initial support for the devcontainers ecosystem
Users can now have their devcontainer.json files scanned for dependency updates. This change introduces the full plumbing for the devcontainers ecosystem, including file fetching, parsing, updating, and version checking, allowing Dependabot to detect and propose updates for dev container configurations.
devcontainers/lib/dependabot/devcontainers · high confidence
Add native Conda ecosystem support
Introduced a complete, native implementation for the Conda package manager ecosystem. This includes a registry client to fetch package metadata from anaconda.org, a file fetcher to process environment.yml files, a parser to extract dependencies, an updater to modify environment files, and a metadata finder to resolve package details. The implementation supports simplified Conda version constraints and pip dependencies within environment files, while explicitly rejecting fully qualified specifications with build strings. This enables Dependabot to monitor and update Conda-based projects.
conda/lib/dependabot/conda · high confidence
Add native JavaScript helpers for Bun, npm, pnpm, and Yarn
This change introduces a new \bun/helpers\ directory containing native JavaScript helper functions for various package managers. For npm, it adds a \conflicting-dependency-parser\ and a \vulnerability-auditor\ that use \@npmcli/arborist\ to detect dependency conflicts and audit for security vulnerabilities. For npm 6, it provides utilities to update dependencies, check peer dependencies, and manage lockfiles. For pnpm, it adds a lockfile parser. For Yarn, it includes a \conflicting-dependency-parser\, a \fix-duplicates\ utility, and helpers for updating dependencies and lockfiles. These helpers are designed to be called from Ruby code via \run.js\, passing arguments via stdin and returning JSON to stdout, allowing the system to utilize package managers' internal APIs and native tooling.
bun/helpers · high confidence
Add native helper for Bundler 4 support
Introduces a new \bundler/helpers/v4\ directory containing a dedicated native helper tree for Bundler 4. This includes a build script that installs and isolates Bundler 4.x, along with Ruby modules for resolving version constraints, parsing Gemfiles and lockfiles, updating lockfiles, and identifying conflicting dependencies. The helper also applies monkey patches to handle Bundler 4 API changes, such as \Index\#search\_all\ removal, Git source authentication, and empty checksum metadata handling.
bundler/helpers/v4 · high confidence
Add sbt ecosystem support for dependency updates
Users can now have their SBT (Scala Build Tool) projects scanned and updated by Dependabot. This change introduces the full implementation for the \sbt\ ecosystem, including file fetching, parsing, updating, and metadata finding. The implementation leverages Coursier for native dependency resolution and supports resolving dependencies defined via Scala \val\ references in \build.sbt\ and \project/\ files. It also handles SBT plugin cross-versioning and custom Maven repository resolvers.
sbt · high confidence
Add support for .NET SDK version updates
Introduce a new \dotnet\_sdk\ ecosystem that enables Dependabot to detect, parse, and update \.NET SDK\ versions specified in \global.json\ files. This includes a file fetcher to locate \global.json\, a parser to extract SDK version and metadata (such as \allowPrerelease\ and \rollForward\), an update checker that queries the official .NET release metadata for the latest versions, and an updater that modifies the \global.json\ file. The implementation also includes a custom version class to handle .NET's non-semver versioning scheme and metadata finding to link to the .NET SDK GitHub repository.
_dotnet\sdk/lib · high confidence
Add support for Azure, Bitbucket, CodeCommit, and template-based branch naming
The PullRequestCreator now supports creating pull requests on Azure DevOps, Bitbucket, and AWS CodeCommit, in addition to the existing GitHub and GitLab integrations. Each new provider (Azure, Bitbucket, CodeCommit) includes its own creator class handling commit and pull request creation with platform-specific limits and behaviors. Additionally, a new BranchNameTemplate class and BranchNamer refactoring introduce configurable branch naming strategies (solo, group, multi-ecosystem) with template-based naming, allowing users to customize branch name formats and enforce stricter validation rules for branch names.
_common/lib/dependabot/pull\_request\creator · high confidence
Add support for Git submodules
The \git\_submodules\ directory now contains the complete implementation for the Git submodules ecosystem, including file fetching, parsing, updating, and metadata finding. This adds the ability for Dependabot to detect, parse, and update dependencies defined in \.gitmodules\ files across GitHub, GitLab, and Azure repositories. The implementation includes a \PackageDetailsFetcher\ to retrieve available versions and a \LatestVersionFinder\ that respects cooldown periods. Tests are provided for all components.
_git\submodules · high confidence
Add support for Rust toolchain updates
Dependabot can now manage Rust toolchain dependencies. This adds a new \rust\_toolchain\ updater that detects \rust-toolchain\ and \rust-toolchain.toml\ files, parses version or channel specifications (such as \stable\, \beta\, \nightly\, or specific versions like \1.72.0\), and generates pull requests to update them to the latest available release.
_rust\toolchain · high confidence
Add support for parsing PEP 735 dependency groups and UV tool sources
The \uv/helpers\ module now includes new helper functions to parse \pyproject.toml\ files, specifically supporting PEP 735 dependency groups and \tool.uv\ path sources. The \parser.py\ file was added to handle these new TOML sections, while \hasher.py\ was added to manage dependency hashing. These changes enable the tool to correctly identify and process optional and build-system dependencies defined in modern Python project configurations.
uv/helpers · high confidence
Add support for parsing devcontainer feature dependencies
The Dependabot parser for the devcontainers ecosystem now extracts feature dependencies from devcontainer configuration files. The new \FeatureDependencyParser\ invokes the \devcontainer\ CLI to identify outdated features, filtering out SHA-pinned versions and deprecated features. This enables Dependabot to track and propose updates for devcontainer features alongside other dependency types.
_devcontainers/lib/dependabot/devcontainers/file\parser · high confidence
Add support for the Dart (pub) ecosystem
Introduces a new \pub\ ecosystem integration for Dart packages. This includes the core Ruby classes for file fetching, parsing, updating, and metadata finding, along with native Dart helpers for dependency services and SDK version inference. The update checker now supports security updates, version resolution, and requirements updates specific to the pub package manager.
pub · high confidence
Add support for the vcpkg package manager
Dependabot can now manage dependencies for the vcpkg C++ package manager. This adds support for updating the \builtin-baseline\ in \vcpkg.json\, managing \default-registry\ and \registries\ in \vcpkg-configuration.json\, and updating port \version\>=\ constraints. The implementation includes a Dockerfile to install vcpkg in the updater image, along with the necessary Ruby classes for file fetching, parsing, updating, and metadata finding. Security updates for vcpkg ports are also supported, with the system capable of raising baselines, adding version constraints, or applying overrides to fix vulnerabilities.
(repo-wide) · high confidence
Add support for updating Helm charts and container images
Dependabot can now manage updates for Helm charts and container images defined in Helm \Chart.yaml\ and \values.yaml\ files. This includes parsing dependencies from Helm chart files, updating version constraints in \Chart.yaml\, and updating image tags in \values.yaml\. The implementation adds new files for fetching, parsing, and updating Helm dependencies, along with helper utilities for interacting with Helm and OCI registries.
helm · high confidence
Add support for updating pre-commit additional dependencies
Users can now have Dependabot update \additional\_dependencies\ in pre-commit hook configurations. This change introduces a new architecture for handling language-specific dependencies (Python, Node, Go, Ruby, Rust, and Dart) within pre-commit hooks, allowing Dependabot to detect and update these transitive dependencies alongside the main hook versions.
_pre\commit · high confidence
Add v2 monkey patches for Bundler compatibility
Added four new monkey patches in the v2 Bundler helper to improve compatibility and fix issues with upstream Bundler behavior. The \definition\_bundler\_version\_patch\ prevents the helper from failing when the Gemfile specifies a Bundler version that differs from the one in use. The \definition\_ruby\_version\_patch\ enables the helper to read the Ruby version from a \.ruby-version\ file and inject it into the dependency resolution process. The \endpoint\_specification\_metadata\_patch\ prevents resolution failures caused by empty checksum metadata in registry responses. The \git\_source\_patch\ converts SSH-based GitHub URLs to HTTPS to avoid authentication issues, and ensures gemspecs in git sources are properly evaluated and cached.
_bundler/helpers/v2/monkey\patches · high confidence
Added Bazel file update support for Bzlmod and Workspace files
Users can now have Bazel dependencies updated via Dependabot. This change introduces new updaters for \bzlmod\ (MODULE.bazel) and \workspace\ (WORKSPACE) files. The \BzlmodFileUpdater\ handles updates to \bazel\_dep\ declarations and generates or updates \MODULE.bazel.lock\ lockfiles by invoking \bazel mod tidy\. The \WorkspaceFileUpdater\ updates \http\_archive\ and \git\_repository\ declarations in \WORKSPACE\ files. A \DeclarationParser\ is also added to parse Bazel build file declarations.
_bazel/lib/dependabot/bazel/file\updater · high confidence
Added Bazel update checker and requirements updater
A new Bazel ecosystem is now supported, introducing a RegistryClient to fetch module metadata and versions from the bazel-central-registry, and a RequirementsUpdater to manage dependency version updates. This enables Dependabot to monitor and update Bazel-based projects.
_bazel/lib/dependabot/bazel/update\checker · high confidence
Added Elm package details fetcher
A new PackageDetailsFetcher class has been introduced for the Elm ecosystem, enabling the system to retrieve and parse package release information from the Elm package registry. This addition supports the broader refactor to implement cooldown logic for package fetching, allowing Dependabot to access detailed release metadata for Elm packages.
elm/lib/dependabot/elm/package · high confidence
Added GemNetHttpAdapter for WebMock integration
A new adapter class, GemNetHttpAdapter, has been added to the spec helpers to enable WebMock to intercept and mock requests made by Ruby's standard library Gem::Net::HTTP. This allows tests to simulate HTTP responses without making real network calls, improving test isolation and speed.
_bundler/helpers/spec\helpers · high confidence
Added lockfile generation for Bun dependency graphing
A new LockfileGenerator class has been introduced for the Bun package manager, enabling the system to automatically generate a bun.lock file during dependency graphing. The generator writes package.json and .npmrc files to a temporary directory, then executes 'bun install' to produce the lockfile. Notably, if no .npmrc file is present in the repository, the generator creates one from stored credentials, ensuring that private registry authentication is handled automatically during the graphing process.
_bun/lib/dependabot/bun/dependency\grapher · high confidence
Added package details fetching for Dev Containers ecosystem
A new \PackageDetailsFetcher\ class has been introduced for the Dev Containers ecosystem. This component is responsible for retrieving package release information and metadata by executing the \devcontainer features info tags\ command and querying container registries (such as GitHub Container Registry) to fetch version and release date details for packages.
devcontainers/lib/dependabot/devcontainers/package · high confidence
Added support for private registries and Helm chart detection
Users can now authenticate with private Docker registries, including AWS ECR, via the new CredentialsFinder utility which handles registry-specific credential resolution and AWS token generation. Additionally, the system can now detect Helm chart files by recognizing filenames matching the pattern 'values\.yaml' or 'values\.yml' through the new likely\_helm\_chart? helper.
docker/lib/dependabot/shared/utils · high confidence
Added support for the Bun package manager
A new implementation for the Bun package manager has been added to Dependabot. This includes the core Ruby classes for file fetching, parsing, updating, and error handling, along with registration in the package manager lookup table. Users can now use Dependabot to manage dependencies for Bun-based projects.
bazel/lib/dependabot, bun/lib/dependabot · high confidence
Bun ecosystem support for update checking
Added new classes to support the Bun package manager ecosystem, including \ConflictingDependencyResolver\, \DependencyFilesBuilder\, \LatestVersionFinder\, \LibraryDetector\, \RequirementsUpdater\, \SubdependencyVersionResolver\, \VersionResolver\, and \VulnerabilityAuditor\. These components enable Dependabot to detect dependency conflicts, resolve versions, update requirements, and audit for vulnerabilities specifically for Bun projects.
_bun/lib/dependabot/bun/update\checker · high confidence
Centralized dependency management for all supported ecosystems
The \omnibus\ gem has been introduced to serve as a central registry that requires and exposes all supported package manager ecosystems (including Bazel, Bun, Conda, Deno, Docker, Julia, Nix, OpenTofu, and others). This change consolidates access to every ecosystem's functionality through a single entry point, ensuring that all supported package managers are loaded and available for use.
omnibus · high confidence
Composer ecosystem implementation for PHP dependency management
Added the core components for the Composer ecosystem, including file fetching, parsing, updating, and metadata finding. This enables Dependabot to manage PHP dependencies by reading composer.json and composer.lock files, detecting package and PHP versions, and identifying security vulnerabilities. The implementation includes strict typing with Sorbet, support for artifact and path dependencies, and integration with Packagist for version resolution.
composer/lib/dependabot/composer · high confidence
Docker ecosystem support added
Added support for Docker images as a first-class dependency type. Users can now track and update Docker images in Dockerfiles, Containerfiles, and Kubernetes YAML files. The update checker handles tag and digest updates, respects cooldowns, and validates image metadata via OCI annotations. This enables Dependabot to propose updates for container images alongside other package managers.
docker/lib/dependabot/docker · high confidence
Extracted shared file handling logic for Docker, Kubernetes, and Helm manifests
The \docker/lib/dependabot/shared\ directory now contains new, fully typed base classes (\SharedFileFetcher\, \SharedFileParser\, \SharedFileUpdater\) that encapsulate common logic for fetching, parsing, and updating Dockerfiles and YAML-based manifests (Kubernetes, Helm, Docker Compose). These shared components handle tasks like stripping BOMs from YAML, validating encoding, and managing image/digest updates, providing a reusable foundation for the Docker ecosystem's file operations.
docker/lib/dependabot/shared · high confidence
Go modules ecosystem restructured into a dedicated directory with native helpers
The Go modules ecosystem code has been reorganized into a dedicated \go\_modules/\ directory, separating it from the common shared code. This change introduces a new native helper binary built from Go source code (\go\_modules/helpers/\) to handle specific operations like resolving VCS remotes and normalizing Azure DevOps URLs. The directory now includes its own \Dockerfile\ for building the native helper, a \.bundle/config\ for Ruby dependencies, and a \.rubocop.yml\ for linting. The Ruby code in \go\_modules/lib/\ now registers the Go modules file fetcher, parser, and grapher, while the native helper provides a JSON-based interface for Go-specific tasks.
_go\modules · high confidence
Implement file updater for Devcontainers
Added a new \ConfigUpdater\ class in \devcontainers/lib/dependabot/devcontainers/file\_updater/config\_updater.rb\ to handle updating Devcontainer configuration files. This implementation enables Dependabot to automatically update Devcontainer dependencies by running the \devcontainer upgrade\ command and modifying the manifest and lockfile to reflect the new version or requirement.
_devcontainers/lib/dependabot/devcontainers/file\updater · high confidence
Initial implementation of Maven ecosystem support
This change introduces the complete Maven package manager implementation within the \maven\ directory. It includes the core components: \FileFetcher\ to retrieve \pom.xml\ and related files, \FileParser\ to extract dependencies, \PropertyValueFinder\ to resolve Maven properties, and \RepositoriesFinder\ to locate artifact repositories. The implementation also adds a \Dockerfile\ to build the Maven runtime environment, configuration files (\.bundle/config\, \.gitignore\, \.rubocop.yml\), and a \README.md\. This provides the foundational infrastructure for Dependabot to manage Maven-based Java projects.
maven · high confidence
Initial implementation of the Hex (Elixir) ecosystem support
This change introduces the complete implementation for the Hex package manager, enabling Dependabot to manage Elixir dependencies. It includes the core logic for fetching, parsing, and updating mix files and lockfiles, alongside native helper scripts for Elixir and Erlang (Elixir 1.19.5, Erlang 27, Hex 2.3.1). The addition allows the platform to detect, track, and propose updates for Elixir projects.
hex · high confidence
Initial support for the Julia ecosystem
Dependabot now supports updating dependencies in Julia projects. This includes parsing \Project.toml\ and \Manifest.toml\ files, resolving dependencies via Julia's Pkg manager, and fetching version information from the General registry. The implementation leverages a native Julia helper (\DependabotHelper.jl\) to handle complex versioning and compatibility logic, and includes support for Julia workspaces where multiple packages share a common manifest file.
bazel/lib/dependabot/bazel, julia · high confidence
Introduce 'silent' ecosystem for isolated integration testing
Added a new 'silent' package manager ecosystem designed for integration testing the updater code without making network calls. This minimal ecosystem uses local JSON files to list available versions, allowing tests to run in isolation. The change includes the core Ruby implementation files (file fetcher, parser, updater, metadata finder, etc.) and a comprehensive suite of Go-based end-to-end tests that validate update, security, and grouping behaviors.
silent · high confidence
Introduce .NET package correlation tooling for NuGet updates
The NuGet updater now includes a new \DotNetPackageCorrelation\ CLI tool and associated test suite. This tooling parses .NET Core release notes and markdown files to build a mapping of which SDK packages shipped with specific runtime packages. This enables the updater to more accurately determine compatible versions for transitive dependencies by correlating them with the .NET SDK version, improving the precision of update suggestions for .NET projects.
nuget/helpers · high confidence
Introduce Bundler 2 native helper implementation
Added new native helper files (bundler\_version\_constraint.rb, functions.rb) that implement the core logic for interacting with Bundler 2, including version constraint resolution, dependency sourcing, lockfile updating, and conflict detection. This provides the underlying functionality for the Bundler 2 support feature.
bundler/helpers/v2/lib · high confidence
Introduce DependencyGraphers base class and generic fallback for dependency graphing
Added a new \DependencyGraphers\ module with a \Base\ class and a \Generic\ fallback implementation to convert parsed dependencies into a structured graph for GitHub's Dependency Submission API. The \Base\ class introduces typed structures (\ResolvedDependency\, \ManifestGroup\, \ManifestGroupSnapshot\) and a \prepare!\ hook for ecosystem-specific graphing, while the \Generic\ class provides a default strategy that attributes dependencies to the right-most dependency file (typically the lockfile) and maps package managers to Package-URL (PURL) types. This establishes the foundation for ecosystem-specific graphers to inherit from, with the generic implementation ensuring existing functionality continues to work during the transition.
_common/lib/dependabot/dependency\graphers · high confidence
Introduce DependencySet to track multiple versions of dependencies
Added a new \DependencySet\ class that allows the system to track and combine multiple versions of the same dependency. This enables the tool to preserve all encountered versions of a dependency, merging their attributes (such as requirements and subdependency metadata) while maintaining insertion order. This change supports scenarios where a single dependency name maps to different versions across the project.
_common/lib/dependabot/file\parsers/base · high confidence
Introduce Elm JSON file updater for dependency updates
Added a new \ElmJsonUpdater\ class that handles updating \elm.json\ files by locating and replacing specific dependency version requirements within the JSON content. This enables the Dependabot system to automatically update Elm package versions in the project's dependency manifest.
_elm/lib/dependabot/elm/file\updater · high confidence
Introduce FileFetcher base class and documentation
Added a new \Dependabot::FileFetchers::Base\ class and a \README.md\ to the \common/lib/dependabot/file\_fetchers\ directory. The base class defines the core interface for fetching dependency files, including methods like \required\_files\_in?\, \required\_files\_message\, and \files\. It also includes logic for handling git submodules, retrying transient git clone errors, and managing repository contents paths. The documentation explains the public API and how to implement new file fetchers for different languages.
_common/lib/dependabot/file\fetchers · high confidence
Introduce Gradle ecosystem support
Added the Gradle ecosystem to Dependabot, enabling the detection, parsing, and updating of Gradle-based Java/Kotlin projects. This includes support for \build.gradle\ and \build.gradle.kts\ files, version catalogs (\libs.versions.toml\), Gradle wrapper updates, and included builds. The implementation provides file fetching, parsing, and updating capabilities for Gradle dependencies, plugins, and properties, along with a Dockerfile for the update environment.
gradle · high confidence
Introduce Julia language support via the new DependabotHelper.jl module
Add a new Julia helper module (DependabotHelper.jl) that enables Dependabot to manage Julia projects. The module provides functions to parse Project.toml and Manifest.toml files, discover package versions and metadata from registries, and handle custom registries. It supports Julia workspaces, batch operations for performance, and precompilation for faster startup. This adds the foundational capability to detect, parse, and update Julia dependencies.
julia/helpers/DependabotHelper.jl · high confidence
Introduce base FileUpdater classes for managing dependency and artifact file updates
Added a new \FileUpdaters::Base\ class that provides a shared foundation for language-specific file updaters, including common methods for checking file changes and updating dependencies. Introduced \FileUpdaters::ArtifactUpdater\ to handle arbitrary modified files within a git directory, supporting create, update, and delete operations with proper encoding and binary file detection. Added \FileUpdaters::VendorUpdater\ as a specialization of \ArtifactUpdater\ that automatically flags files as vendored, ensuring correct handling during grouped updates. These changes enable Dependabot to more robustly manage dependency files and supplementary artifacts across different ecosystems.
_common/lib/dependabot/file\updaters · high confidence
Introduce generic package version-finding and release-cooldown logic
Added new classes to the common library to support a generic package version finder and release cooldown filtering. The new \PackageDetails\ and \PackageRelease\ models store metadata about a package, including its available versions, distribution tags, and release details. The \PackageLatestVersionFinder\ abstract class provides a unified interface for finding the latest version, tag, and release, while applying filters for yanked versions, ignored versions, and security advisories. A new \ReleaseCooldownOptions\ class and associated filtering logic allow the system to temporarily suppress updates based on configurable cooldown periods, with a fallback to the current version if all releases are filtered out.
common/lib/dependabot/package · high confidence
Introduce native Composer v2 helper for PHP dependency updates
Added a new native helper for Composer v2, located in the composer/helpers/v2 directory. This includes a build script that copies and installs the helper, a PHP entry point (bin/run) that routes update, version-check, and hashing requests, and configuration files for PHP-CS-Fixer and PHPStan. This change enables the system to use a dedicated, native binary for handling Composer v2 ecosystem updates, rather than relying on the previous method.
composer/helpers · high confidence
Introduce native NuGet updater with .NET SDK installation
The NuGet ecosystem now utilizes a native updater tool built with .NET 10, replacing the previous Ruby-based implementation. This change introduces a new \NuGetUpdater\ CLI that handles file cloning, SDK installation from \global.json\ files, and dependency graph generation. The update process now automatically installs required .NET SDKs and targeting packs based on repository configuration, improving performance and reliability for .NET projects.
nuget · high confidence
Introduce new Bundler 2 native helper functions
Added new native helper classes for the Bundler 2 integration: \ConflictingDependencyResolver\ to identify dependency conflicts, \DependencySource\ to determine gem sources, \FileParser\ to parse lockfiles and gemfiles, \ForceUpdater\ to force-update dependencies, \LockfileUpdater\ to regenerate lockfiles, and \VersionResolver\ to resolve latest versions. These files implement the core logic for managing Ruby dependencies using the Bundler 2 API.
bundler/helpers/v2/lib/functions · high confidence
Introduce new development and release scripts
The \bin\ directory now includes several new executable scripts to streamline development workflows. \bin/dry-run.rb\ allows developers to simulate an update run for a given repository without creating a pull request, supporting a wide range of package managers. \bin/test\ provides a convenient way to run tests within the Docker development shell for a specific ecosystem. \bin/docker-dev-shell\ manages the Docker-based development environment, building per-ecosystem images and handling container lifecycle. \bin/ci-test\ simulates the CI process for a given suite. \bin/bump-version.rb\ automates the process of updating version numbers in the project's Gemfile.lock and common library. Additionally, \bin/lint\ and \bin/rubocop\ are added to run shellcheck and RuboCop respectively, ensuring code quality.
bin · high confidence
Introduce standalone \`dependabot-terraform\` ecosystem package
The Terraform ecosystem is now a standalone package (\terraform/\) with its own \Gemfile\, Dockerfile, and helper build scripts, separating it from the core monorepo structure. This includes the full implementation of the Terraform file fetcher, parser, updater, and metadata finder, along with a native helper script to download and verify the \hcl2json\ binary. The package registers itself with the central \FileFetchers\, \FileParsers\, and \FileUpdaters\ registries, enabling Dependabot to detect, parse, and update Terraform configurations and provider dependencies.
terraform · high confidence
Introduce support for the Python \`uv\` package manager
Added a new \uv\ ecosystem to Dependabot, enabling the detection, parsing, and updating of \uv.lock\ and \pyproject.toml\ files. This includes a dedicated file fetcher to retrieve workspace members and metadata, a parser to extract dependencies from TOML and lockfiles, and a dependency grapher that builds the dependency tree from \uv.lock\. The implementation also provisions Python versions (3.10–3.14) and the \uv\ binary in the updater's Docker environment.
uv · high confidence
Introduce typed base class for file parsers
The \Dependabot::FileParsers::Base\ class is introduced as a strongly typed, abstract base for all language-specific file parsers. It enforces a consistent interface for parsing dependencies, managing credentials, and handling repository context. This change provides a standardized foundation for implementing new parsers and ensures type safety across the file parsing layer.
_common/lib/dependabot/file\parsers · high confidence
Introduce v2 native helper for Bundler 2 support
Added a new v2 native helper tree for Bundler 2, including a build script that installs the requested Bundler version and a run.rb entry point that activates Bundler 2 with version constraints and applies necessary monkey patches. This isolates Bundler 2 functionality from other helper versions.
bundler/helpers/v2 · high confidence
Native conda update checking and requirement updating
Users with conda dependencies now have native support for version updates. A new \LatestVersionFinder\ resolves the latest available versions by querying the Conda registry (with fallback to pip for compatible packages), and a \RequirementsUpdater\ modifies \environment.yml\ files to reflect new versions according to the configured update strategy (e.g., widening ranges or bumping versions). A \RequirementTranslator\ converts conda-style version constraints into pip-compatible formats where necessary.
_conda/lib/dependabot/conda/update\checker · high confidence
New API clients for Azure, Bitbucket, CodeCommit, and GitHub releases
Added new API client implementations for Azure DevOps, Bitbucket, AWS CodeCommit, and GitHub releases, each with Sorbet strict typing and retry logic where applicable. These clients provide the underlying HTTP interactions for their respective version control systems, enabling Dependabot to fetch repository contents, commit hashes, and pull request data from these platforms.
common/lib/dependabot/clients · high confidence
New Composer v2 helper classes for dependency updates
Added new helper classes in the Composer v2 integration to manage plugin registration, error handling, and update operations. The \DependabotPluginManager\ overrides package registration to safely ignore PHP\_CodeSniffer setup errors during lockfile-only installs. The \ExceptionIO\ class captures and throws runtime exceptions for specific Composer resolution errors. The \Updater\ and \UpdateChecker\ classes implement the core logic for running Composer update operations, handling credentials, and retrieving the latest resolvable versions of dependencies.
composer/helpers/v2 · high confidence
New rake tasks to scaffold and update ecosystem boilerplate
Developers can now use \rake ecosystem:scaffold\, \rake ecosystem:update\_infrastructure\, and \rake ecosystem:create\ to automatically generate the directory structure, template files, and supporting infrastructure for a new ecosystem. The \ecosystem:scaffold\ task creates the initial boilerplate, while \update\_infrastructure\ updates CI workflows, gemspecs, and other configuration files to include the new ecosystem.
rakelib · high confidence
New versioning and wildcard matching utilities
The common library now includes a \Dependabot::Version\ constant set to 0.390.0, and introduces a new \WildcardMatcher\ class that provides a typed method for matching strings against wildcard patterns (e.g., \\*\), supporting both Ruby and Sorbet type annotations.
common/lib · high confidence
Register Bundler as a supported package manager
The Bundler package manager is now registered within the application, enabling the system to fetch, parse, and update Ruby dependencies managed by Bundler. This includes loading the necessary modules for file handling, versioning, and update checking, as well as configuring production dependency detection for the 'bundler' ecosystem.
bundler/lib/dependabot, composer/lib/dependabot · high confidence
Rust/Cargo ecosystem implementation
Added support for the Rust/Cargo ecosystem, enabling Dependabot to fetch, parse, and update Cargo.toml and Cargo.lock files. This includes handling workspace dependencies, path dependencies, and custom registries, as well as stripping credential-provider settings from .cargo/config.toml to ensure secure authentication via environment variables.
cargo/lib/dependabot/cargo · high confidence
Standardize project configuration and development environment
The repository introduces a suite of new configuration files to standardize code style, formatting, and development workflows. A \.editorconfig\ enforces consistent indentation, line endings, and character encoding across editors. A \.rubocop.yml\ file configures the RuboCop linter with specific rules for Ruby, RSpec, and Sorbet, including enabling new cops and setting a target Ruby version of 3.3. A \.codespellrc\ file configures the codespell tool to ignore specific technical terms and file types. Additionally, \.gitignore\ and \.dockerignore\ files are added to exclude build artifacts, environment files, and IDE-specific directories from version control and Docker builds. The \.gitattributes\ file ensures consistent line endings and file type detection, while \.git-blame-ignore-revs\ tracks commits to ignore in git blame for style changes. Finally, \.gitmodules\ is added to manage the NuGet.Client and dotnet-core submodules.
(repo-wide) · high confidence
Support for building path dependencies from lockfile data
A new PathDependencyBuilder class has been added to the Composer file fetcher. This component is responsible for constructing path dependencies by extracting their content from the lockfile. If a path dependency cannot be built, the system currently returns nil, which may result in errors in the UpdateChecker or FileUpdater. The implementation includes strict typing for the lockfile parsing and content building logic.
_composer/lib/dependabot/composer/file\fetcher · high confidence
Architecture
Extracted changelog, commits, and release finding logic into shared base classes
Moved the \ChangelogFinder\, \ChangelogPruner\, \CommitsFinder\, and \ReleaseFinder\ classes into the \common/lib/dependabot/metadata\_finders/base\ directory. This refactoring consolidates metadata-finding logic into shared base classes, allowing different package managers to inherit or reuse these implementations rather than each maintaining their own version of these finders.
_common/lib/dependabot/metadata\finders/base · high confidence
Python helpers refactored into modular lib files
The Python helper scripts have been refactored into a structured library under python/helpers/lib, splitting functionality into separate modules for hashing (hasher.py), parsing (parser.py), and a package init file. This reorganization improves code maintainability and separation of concerns within the Python ecosystem support.
python/helpers · high confidence
Refactor Cargo file updating into dedicated updater classes
The Cargo file update logic has been refactored into three new classes: \LockfileUpdater\, \ManifestUpdater\, and \WorkspaceManifestUpdater\. This change separates the concerns of updating \Cargo.lock\, individual \Cargo.toml\ manifests, and workspace-level dependency declarations, making the codebase more modular and easier to maintain.
_cargo/lib/dependabot/cargo/file\updater · high confidence
Refactored Cargo update checking into dedicated classes
The Cargo update checker logic has been restructured into four new classes: FilePreparer, LatestVersionFinder, RequirementsUpdater, and VersionResolver. This refactoring separates concerns for preparing dependency files, finding the latest resolvable version, updating requirements, and resolving versions, improving code maintainability and type safety through Sorbet strict typing.
_cargo/lib/dependabot/cargo/update\checker · high confidence
Reorganize and retype the Bundler ecosystem implementation
The Bundler package manager implementation has been reorganized into a new directory structure (bundler/lib/dependabot/bundler) with all classes strictly typed using Sorbet. This includes new or refactored components such as CachedLockfileParser, FileFetcher, FileParser, FileUpdater, Helpers, Language, MetadataFinder, NativeHelpers, PackageManager, Requirement, UpdateChecker, and Version. The reorganization groups related logic for parsing, fetching, updating, and checking updates for Ruby/Bundler projects, improving code maintainability and type safety.
bundler/lib/dependabot/bundler · high confidence
Behavioural changes
Add immutable Git credential helper script
A new executable script, common/bin/git-credential-store-immutable, has been added to the repository. This Ruby script acts as a wrapper for the Git credential-store, restricting operations to the 'get' command only. By preventing 'store' and 'erase' commands from mutating the credential store, it enforces an immutable approach to credential management, ensuring that credentials cannot be written or deleted through this helper.
common/bin · high confidence
Bazel tooling now uses a shared Gemfile for dependency updates
A new configuration file has been added to the Bazel directory to point to a shared Gemfile located in the dependabot-updater directory. This change aligns the Bazel environment with the project's centralized dependency update strategy, ensuring that Bazel's Ruby dependencies are managed consistently with the rest of the codebase.
bazel/.bundle · high confidence
Centralized update-checker base class and shared filtering logic
The \common/lib/dependabot/update\_checkers\ directory now provides a shared \Base\ class and supporting modules (\CooldownCalculation\, \VersionFilters\) that all language-specific update checkers inherit from. This refactor consolidates common update-checking logic—including version filtering against security advisories, cooldown window calculations, and requirement update strategies—into the common library, allowing ecosystem-specific checkers to focus on their unique resolution logic while reusing shared behavior.
_common/lib/dependabot/update\checkers · high confidence
Configure Bundler to use the project's Gemfile
A new Bundler configuration file has been added to the devcontainers directory, setting BUNDLE\_GEMFILE to point to the Gemfile located in the ../dependabot-updater directory. This ensures that Bundler uses the correct dependency definitions when running in the devcontainer environment.
devcontainers/.bundle · high confidence
Configure Conda to use a specific Gemfile for dependency updates
A new configuration file at conda/.bundle/config has been added to specify the Bundler gemfile path as '../dependabot-updater/Gemfile'. This change directs the Conda environment's bundle operations to use the Gemfile located in the dependabot-updater directory, ensuring consistent dependency management for that specific context.
conda/.bundle · high confidence
Consolidate Docker and Docker Compose module registrations
The Docker and Docker Compose package managers are now registered via consolidated top-level entry points (docker.rb and docker\_compose.rb) that require their respective file fetchers, parsers, and updaters. Both modules are configured with 'strong' type checking, register their label details for pull request creation, and register production checks. This change ensures that the version, requirement, and metadata finder classes are correctly associated with their respective package managers.
docker/lib/dependabot · medium confidence
Devcontainers: Add cooldown filtering to version updates
The devcontainers update checker now applies a cooldown period to new releases. The new LatestVersionFinder filters out versions that are too recent, using a configurable cooldown window to prevent immediate updates. This ensures that only releases outside the cooldown period are considered for updates.
_devcontainers/lib/dependabot/devcontainers/update\checker · high confidence
Extracted dependency source logic into a dedicated class
The logic for determining a dependency's source type and fetching version information has been extracted from the main LatestVersionFinder into a new DependencySource class. This refactoring improves code organization and allows for more precise handling of different dependency sources (RubyGems, private registries, Git) with dedicated methods for each.
_bundler/lib/dependabot/bundler/update\_checker/latest\_version\finder · high confidence
Improved PR message formatting and sanitization
Pull request messages now feature more robust sanitization of links and mentions, including stricter handling of GitHub references, team mentions, and code blocks to prevent accidental notifications or broken links. The message builder has been refactored to extract title composition into a dedicated TitleBuilder, issue linking into an IssueLinker, and metadata presentation into a MetadataPresenter, resulting in cleaner, more maintainable code. Additionally, the system now supports zero-width spaces in @mentions to prevent accidental notifications while preserving text formatting.
_common/lib/dependabot/pull\_request\_creator/message\builder · high confidence
Improved error handling and stability for npm, Yarn, and pnpm
The npm\_and\_yarn ecosystem received a comprehensive set of fixes and improvements to handle various edge cases and errors more gracefully. This includes adding exception handling for override failures, registry auth failures, and Yarn-specific errors (such as YN0035 and YN0082). The update also addresses issues with empty package manager names, invalid package names, and malformed lockfiles. Additionally, it fixes bugs related to peer dependency conflicts, sub-dependency updates, and private registry configurations, ensuring that the tooling is more robust against network issues, invalid data, and configuration errors.
_npm\_and\yarn · high confidence
Improved error handling and type safety in common library
The common library received a significant overhaul to improve reliability and maintainability. Key changes include the introduction of a \SecurityAdvisory\ class to determine if a version is vulnerable, and the addition of a \Dependency\#direct?\ method to distinguish direct from transitive dependencies. Error handling was enhanced by adding specific error classes like \AllVersionsIgnored\ and \DependencyFileNotParseable\, and by sanitizing credentials in error messages. The codebase also saw a major push for strict typing (Sorbet), replacing \T.untyped\ with specific types across 16+ files, and removing \OpenStruct\ usage. Additionally, the \GitCommitChecker\ was strictly typed, and the \Dependency\ class was moved to the common library to share logic across ecosystems.
common/lib/dependabot · high confidence
Introduce shared metadata finder base class and public API
Adds a new \Dependabot::MetadataFinders::Base\ class that provides a unified interface for retrieving dependency metadata. This base class implements methods for \source\_url\, \homepage\_url\, \changelog\_url\, \changelog\_text\, \upgrade\_guide\_url\, \upgrade\_guide\_text\, \releases\_url\, \releases\_text\, \commits\_url\, and \commits\. It also includes stub methods for \maintainer\_changes\, \install\_script\_changes\, and \attestation\_changes\ to support future behavioral changes. The change includes a \README.md\ documenting the public API and usage for language-specific implementations.
_common/lib/dependabot/metadata\finders · high confidence
Introduces a typed base interface for requirements updaters
Adds a new \base.rb\ file that defines a typed base interface for requirements updaters using Sorbet. This interface enforces the implementation of \updated\_requirements\, \version\_class\, and \requirement\_class\ methods, ensuring that all concrete updater classes adhere to a consistent contract for handling dependency versions and requirements.
_common/lib/dependabot/requirements\updater · medium confidence
Python ecosystem receives numerous bug fixes and stability improvements
The Python ecosystem received a large number of bug fixes and stability improvements. Key changes include fixing Python version defaulting to 3.9 (lowest available) instead of latest when no explicit version is specified, handling wildcards in requirements with non-equality operators, and improving error handling for unreachable git dependencies. Additional fixes address issues with Poetry sub-dependencies, PEP 621 projects, and pip-compile file updates. The changes also include better handling of environment variables, markers, and private registry sources.
python · medium confidence
Refactor Bundler file parsing with Prism and Sorbet
The Bundler file parser has been refactored to use the Prism AST parser instead of the previous parser, improving how Gemfile and gemspec files are processed. This change introduces new classes—FilePreparer, GemfileDeclarationFinder, and GemspecDeclarationFinder—to handle dependency declaration detection. The implementation adds Sorbet type annotations (typed: strong/strict) and leverages Prism for more robust parsing of Ruby code, which should lead to more accurate dependency detection and better handling of complex Gemfile structures.
_bundler/lib/dependabot/bundler/file\parser · high confidence
Refactor Bundler file update logic into dedicated updater classes
The Bundler file update logic has been refactored into dedicated classes for each file type: \GemfileUpdater\, \GemspecUpdater\, \LockfileUpdater\, \RequirementReplacer\, \GitPinReplacer\, \GitSourceRemover\, \GemspecSanitizer\, \GemspecDependencyNameFinder\, and \RubyRequirementSetter\. This change replaces the previous monolithic \FileUpdater\ implementation with specialized components that handle specific update operations, such as replacing version requirements, updating git pins, removing git sources, sanitizing gemspecs, and setting Ruby version requirements.
_bundler/lib/dependabot/bundler/file\_updater, composer/lib/dependabot/composer/file\updater · high confidence
Refactor Composer update checking into dedicated finder and updater classes
The Composer update checking logic has been refactored to improve maintainability and type safety. A new \LatestVersionFinder\ class now encapsulates the logic for determining the latest available version, while a new \RequirementsUpdater\ class handles the transformation of version constraints. The \VersionResolver\ has been updated to use these new classes, introducing stricter typing and better error handling for Composer-specific scenarios like missing PHP extensions and unreachable VCS sources.
_composer/lib/dependabot/composer/update\checker · high confidence
Refactor Hex helper scripts to use structured JSON output and stderr logging
The Hex helper scripts (check\_update, do\_update, parse\_deps, and run) have been rewritten to output structured JSON via stderr instead of raw stdout, and to handle errors and timeouts more robustly. This change improves how dependency updates and checks are reported to the caller, ensuring that log messages do not interfere with the machine-readable output. The \run.exs\ script now decodes and validates JSON responses, while the other scripts use \:logger\ to send logs to stderr, keeping stdout clean for structured data.
hex/helpers · high confidence
Refactor branch naming strategy for improved clarity and maintainability
The branch naming logic has been refactored into a new \Base\ class that centralizes sanitization, word separation, case transformation, and length limiting. Specific strategies (\SoloStrategy\, \DependencyGroupStrategy\, \MultiEcosystemStrategy\) now inherit from this base, each implementing their own \new\_branch\_name\ logic. This change introduces support for configurable \word\_separator\, \branch\_name\_case\, and \template\ parameters, allowing for more flexible and consistent branch name generation across different update types.
_common/lib/dependabot/pull\_request\_creator/branch\namer · high confidence
Refactored Bazel file fetching into specialized fetcher classes
The Bazel file fetching logic has been refactored into distinct, specialized classes to improve maintainability and clarity. A new \PathConverter\ utility handles Bazel label-to-path conversion. New fetchers include \BzlFileFetcher\ for handling \.bzl\ files and their \load()\ dependencies, \IncludeExtractor\ for processing \include()\ statements in \MODULE.bazel\ files, \ModulePathExtractor\ for parsing attributes like \lock\_file\ and \local\_path\_override\, \DirectoryTreeFetcher\ for recursive directory traversal, and \DownloaderConfigFetcher\ for \.bazelrc\ configurations. This change reorganizes the existing \FileFetcher\ responsibilities into these focused components.
_bazel/lib/dependabot/bazel/file\fetcher · high confidence
Refactored Bundler update checker into specialized sub-components
The Bundler update checker logic has been refactored into distinct, specialized classes to improve maintainability and type safety. The \UpdateChecker\ class now delegates to \FilePreparer\ for managing dependency files, \LatestVersionFinder\ for identifying candidate versions, \VersionResolver\ for resolving the final version, \RequirementsUpdater\ for updating version constraints, \ForceUpdater\ for forced updates, \CooldownOptionsBuilder\ for handling release cooldowns, and \ConflictingDependencyResolver\ for identifying blocking dependencies. These components are now fully typed with Sorbet and structured to handle specific parts of the update check process.
_bundler/lib/dependabot/bundler/update\checker · high confidence
Refactored Elm update checker with strict typing and new CLI parser
The Elm update checker has been refactored to improve type safety and parsing logic. A new \CliParser\ class was added to handle parsing of install and upgrade preview text from the Elm CLI, extracting dependency names and versions. The \LatestVersionFinder\ and \Elm19LatestVersionFinder\ classes were updated with Sorbet strict typing, including explicit type signatures for all methods and attributes. Additionally, a \RequirementsUpdater\ class was introduced to manage the transformation of version requirements during updates, supporting range and exact version updates. These changes enhance the reliability and maintainability of the Elm ecosystem's update checking process.
_elm/lib/dependabot/elm/update\checker · high confidence
Refactored build and test scripts for ecosystem modularity
The repository's build and testing infrastructure has been restructured to support independent ecosystem containers. A new \script/\_common\ library provides shared functions for Docker image building, tag mapping, and cache configuration, which are now used by \script/build\ and \script/ci-test-updater\. The \script/dependabot\ script has been updated to mount all ecosystem directories (including new ones like \uv\, \vcpkg\, and \opentofu\) into the CLI container. Additionally, a \script/sorbet-untyped-ratchet\ script was added to enforce a burndown of \T.untyped\ usage in the codebase, and \script/test-rakefile\ was introduced to verify the modularized Rakefile structure.
script · high confidence
Refactored workspace management into a modular, type-safe structure
The workspace implementation has been refactored into separate, specialized classes: a \Base\ abstract class and a \Git\ concrete implementation, along with a new \ChangeAttempt\ class to track success and failure states. This change introduces strict Sorbet typing (\\# typed: strong/strict\) to the workspace module, improving code maintainability and error handling. Users benefit from more robust handling of git operations, including explicit change storage and better debugging of failed attempts.
common/lib/dependabot/workspace · high confidence
Removed Ruby dependency parsing and Dependency class
The Ruby file parser and the Dependency class have been removed from the codebase. This eliminates the ability to parse Ruby/Gemfile dependencies, as the parser relied on the now-removed Dependency class to represent parsed results.
lib/bumper · high confidence
Replace Ruby parser with Prism for Bundler file fetching
The Bundler file fetcher now uses the Prism parser to locate and resolve dependencies, including \eval\_gemfile\, \gemspec\, and \path\ declarations. This change removes all calls to \eval\ during file fetching, which improves security by avoiding the execution of arbitrary code, and provides more robust parsing of Gemfile structures.
_bundler/lib/dependabot/bundler/file\fetcher · high confidence
Standardize Bundler configuration across multiple language packages
The Bundler configuration file (.bundle/config) is added to the bundler, cargo, common, composer, docker, and elm directories. Each file sets BUNDLE\_GEMFILE to point to the shared Gemfile in the dependabot-updater directory, ensuring consistent dependency resolution and test behavior across these components.
(repo-wide) · high confidence
Strictly typed Dependabot config file parsing
The \Dependabot::Config::File\ and \FileFetcher\ classes have been refactored to use Sorbet's strong typing, ensuring that the \dependabot.yml\ configuration file is parsed into strongly-typed objects (\UpdateConfig\, \IgnoreCondition\, \CommitMessageOptions\). This change enforces data integrity for update configurations, including support for \exclude-paths\, \commit-message\ options, and \ignore\ conditions with \update-types\ and \dependency-name\ filters. The \FileFetcher\ now strictly validates the presence of the configuration file, and the \IgnoreCondition\ logic now correctly handles nil versions and transforms update types for version matching.
common/lib/dependabot/config · high confidence
Updated Sorbet type definitions for updated gems
The Sorbet RBI files for several gems have been regenerated to reflect the latest upstream changes. This includes updated type signatures for \faraday\, \rainbow\, \webmock\, \addressable\, \ast\, \aws-eventstream\, \aws-partitions\, \aws-sdk-codecommit\, \aws-sdk-core\, \aws-sdk-ecr\, and \aws-sigv4\. These updates ensure that the static type checker has the most current interface definitions for these dependencies.
sorbet · high confidence
Updater refactors and type safety improvements
The updater has been refactored to use a new \Dependabot::Updater::Operations\ structure, replacing the previous monolithic \Updater.run\ flow with distinct operation classes for tasks like \UpdateAllVersions\ and \RefreshSecurityUpdatePullRequest\. This change improves code organization and testability. Additionally, the codebase has been migrated from \sentry-raven\ to \sentry-ruby\ for error reporting, and significant progress has been made on Sorbet type strictness, with many files now passing at the \typed: strong\ level. The \DependencyGroupEngine\ has been introduced to handle dependency grouping logic, and the \Job\ class has been typed to use structured objects instead of raw hashes.
updater · high confidence
Test coverage
1 commit adding/updating tests in composer/spec/fixtures/git; 2 commits adding/updating tests in cargo/spec/fixtures/git; Add docker-compose fixture files for parser tests; Add dummy package manager test fixtures; Add test fixture for git tag versioning; Add tests for PR message builder components; Add tests for PathDependencyBuilder; Add tests for class registration in Docker and Docker Compose; Added Azure test fixtures for Git operations; Added Bitbucket fixture data for pull request and repository tests; Added Dockerfile fixtures for Docker image parsing tests; Added ECR response fixtures for authentication and error scenarios; Added Elm fixture files for dependency resolution tests; Added Elm spec helper for shared test utilities; Added Ruby gemspec and RubyGems API response fixtures; Added \_\init\\_.py for my-project package; Added changelog fixtures for jsdom, Rails 5.2, and Sentry; Added comprehensive test coverage for Bazel ecosystem support; Added comprehensive test coverage for Cargo file updaters; Added comprehensive test coverage for Cargo update checker components; Added comprehensive test coverage for Composer ecosystem components; Added comprehensive test coverage for the file fetcher base class and shared examples; Added comprehensive tests for Bundler file updater components; Added empty Rust source file for version conflict test fixture; Added initial conda test infrastructure; Added spec helper for Composer tests; Added specs for Composer lockfile and manifest updaters; Added test coverage for Azure, GitHub, and GitLab pull request updaters; Added test coverage for Bundler file parsing components; Added test coverage for Bundler v2 helper functions and patches; Added test coverage for Bundler v2 native helper functions; Added test coverage for core Dependabot models and utilities; Added test coverage for multiple client implementations; Added test coverage for the devcontainers ecosystem; Added test coverage for the dry-run script; Added test fixture for Rust toolchain configuration; Added test fixture for binary file handling; Added test fixture for git upload pack protocol; Added test fixtures for CodeCommit client; Added test fixtures for Julia workspace sub-packages; Added test fixtures for command execution scenarios; Added test fixtures for local path module resolution; Added test fixtures for nested Terraform modules; Added test fixtures for the Bun ecosystem; Added test helper infrastructure for Bundler specs; Added test helper scripts for simulating subprocess errors; Added test infrastructure for Bun ecosystem; Added test infrastructure for the dotnet\_sdk spec; Added test package for Julia helper; Added tests for Bundler ecosystem helpers and spec files; Added tests for Bundler file fetcher components; Added tests for Bundler package details fetching; Added tests for Composer dependency management; Added tests for Dependabot config file fetching and ignore condition logic; Added tests for Docker Compose file handling; Added tests for Docker registry credential resolution; Added tests for Elm package details fetcher; Added tests for GitCommitChecker::SourceDetails; Added tests for PullRequestCreator components; Added tests for branch naming strategies; Added tests for changelog, commits, and release finders; Added tests for class registration in Bundler, Cargo, and Elm; Added tests for package release and cooldown configuration; Added tests for the Bundler dependency source update checker; Added tests for the DependencySet class; Added tests for the Elm ecosystem support; Added tests for the Git workspace utility; Added tests for the common metadata finders base class and shared examples; Added tests for the dotnet\_sdk ecosystem; Added tests for update checker base class, cooldown calculation, and version filtering; Added unit tests for file updater components; Expanded Cargo fixture coverage for manifest edge cases; Expanded test coverage for Cargo ecosystem; Expanded test coverage for Docker ecosystem components; Introduce CI test script for Composer; Introduce automated CI test script for Bundler; Removed obsolete test files and dependencies; Standardized CI test execution across ecosystems; Standardized test environment with coverage and profiling support; Updated Cargo lockfile test fixtures; Updated Ruby gem fixture data for testing; Updated RubyGems API response fixtures for testing.
Dependencies
Routine dependency updates across all helper directories
This update refreshes the dependencies in the /npm\_and\_yarn/helpers, /python/helpers, /composer/helpers/v2, /go\_modules/helpers, and /updater directories. The changes include routine version bumps for various packages such as eslint, jest, npm, and pip-tools, ensuring that the helper tools remain up to date with the latest stable releases.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 45.
Lenses
- Code Health 69
- Architecture 95
- Maturity 69
- Readiness 36
- Security 33
Changes since last survey
- 300 commits — 270 feature/other, 30 fixes
By area
- updater/lib — 43 commits
- common/lib — 34 commits
- npm_and_yarn/helpers — 32 commits
- bun/helpers — 17 commits
- (root) — 14 commits
- python/lib — 12 commits
- npm_and_yarn/lib — 10 commits
- nuget/helpers — 10 commits
- maven/lib — 6 commits
- python/helpers — 6 commits
- cargo/lib — 5 commits
- docker/lib — 5 commits
- npm_and_yarn/spec — 5 commits
- updater/spec — 5 commits
- vcpkg/lib — 5 commits
- cargo/spec — 4 commits
- github_actions/lib — 4 commits
- gradle/Dockerfile — 4 commits
- pre_commit/lib — 4 commits
- uv/Dockerfile — 4 commits
Notable commits
- fix: Add uv grapher regression test for versionless back-references (#15259) (#15778)
- fix: Address review feedback on vcpkg version comparison and fix resolution
- fix: Compute npm audit fix tree on a fresh Arborist instance (#15514)
- fix: Draft fix for path dependency not reachable
- fix: Fix Docker cooldown not respected for multi-arch images missing Last-Modified (#15486)
- fix: Fix Gradle lockfile updates for repos with in-repo convention plugins (#15677)
- fix: Fix RuboCop offenses
- fix: Fix UV DependencyGrapher to detect nested uv.lock in monorepos (#15520)
- fix: Fix codespell typo in updater job spec (#15599)
- fix: Fix gemspec infrastructure updates
- fix: Fix npm ignoring scoped registry issue (#15692)
- fix: Fix pnpm 11 peer dependency checks
- fix: Fix security update jobs failing with dependency_file_not_found for single-directory manifests (#15658)
- fix: Fix some comments that still refer to degraded
- fix: Fix type boundaries in Gradle, Swift, and pre_commit
- fix: Fix typed source validation
- fix: Merge branch 'main' into fix-actions-cooldown-precision-regression
- fix: Merge pull request #15746 from theinfosecguy/fix-dotnet-sdk-preview-version
- fix: Merge pull request #15760 from dependabot/fix-actions-cooldown-precision-regression
- fix: Respect resolutions/overrides and pin Berry wildcard updates to fix spurious NoChangeError (#15701)
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
dependabot/dependabot-core was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 7 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 2ef9fd2f47263a5fa2bc305b129d3c9e88d2a831 — the exact code this score is about.
- Scored under rubric-2026.08.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using localhost:5005/codehealth-analyzer rubric-2026.08.15.