Skip to content

Add Dependabot configuration for automated dependency updates#541

Open
cyber-excel10 wants to merge 2 commits into
Smartdevs17:mainfrom
cyber-excel10:add-dependabot-config
Open

Add Dependabot configuration for automated dependency updates#541
cyber-excel10 wants to merge 2 commits into
Smartdevs17:mainfrom
cyber-excel10:add-dependabot-config

Conversation

@cyber-excel10

Copy link
Copy Markdown
Contributor

Closes #55

Summary

Adds .github/dependabot.yml to enable automated dependency update PRs across all three package ecosystems in this repo, per #55.

What's included

  • npm ecosystem for /api
  • npm ecosystem for /oracle
  • cargo ecosystem for /stellar-lend
  • All three on a weekly update schedule
  • Minor and patch updates grouped per ecosystem to reduce PR noise (per the issue's constraints)

Why

The project currently has no automated mechanism to surface dependency updates, including security patches in transitive dependencies. This config lets Dependabot open update PRs automatically so those can be reviewed and merged on a predictable cadence instead of going unnoticed.

Testing

This is a configuration-only change — no source code is modified. I validated the YAML locally before submitting. Once merged into the default branch, GitHub will pick up the config automatically and Dependabot will run its first scheduled scan.

@vercel

vercel Bot commented Jun 24, 2026

Copy link
Copy Markdown

@cyber-excel10 is attempting to deploy a commit to the smartdevs17's projects Team on Vercel.

A member of the Team first needs to authorize it.

@drips-wave

drips-wave Bot commented Jun 24, 2026

Copy link
Copy Markdown

@cyber-excel10 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@gitguardian

gitguardian Bot commented Jun 25, 2026

Copy link
Copy Markdown

⚠️ GitGuardian has uncovered 7 secrets following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

Since your pull request originates from a forked repository, GitGuardian is not able to associate the secrets uncovered with secret incidents on your GitGuardian dashboard.
Skipping this check run and merging your pull request will create secret incidents on your GitGuardian dashboard.

🔎 Detected hardcoded secrets in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
34253505 Triggered Generic High Entropy Secret bed18b9 docker/devnet/seed-data/accounts.json View secret
34253506 Triggered Generic High Entropy Secret bed18b9 docker/devnet/seed-data/accounts.json View secret
34253507 Triggered Generic High Entropy Secret bed18b9 docker/devnet/seed-data/accounts.json View secret
34253508 Triggered Generic High Entropy Secret bed18b9 docker/devnet/seed-data/accounts.json View secret
34253509 Triggered Generic High Entropy Secret bed18b9 docker/devnet/seed-data/accounts.json View secret
34253510 Triggered Generic High Entropy Secret bed18b9 docker/devnet/seed-data/accounts.json View secret
34253511 Triggered Generic High Entropy Secret bed18b9 docker/devnet/seed-data/accounts.json View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secrets safely. Learn here the best practices.
  3. Revoke and rotate these secrets.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add Dependabot configuration for automated dependency updates

1 participant