Add Dependabot configuration for automated dependency updates#541
Add Dependabot configuration for automated dependency updates#541cyber-excel10 wants to merge 2 commits into
Conversation
|
@cyber-excel10 is attempting to deploy a commit to the smartdevs17's projects Team on Vercel. A member of the Team first needs to authorize it. |
|
@cyber-excel10 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
|
| GitGuardian id | GitGuardian status | Secret | Commit | Filename | |
|---|---|---|---|---|---|
| 34253505 | Triggered | Generic High Entropy Secret | bed18b9 | docker/devnet/seed-data/accounts.json | View secret |
| 34253506 | Triggered | Generic High Entropy Secret | bed18b9 | docker/devnet/seed-data/accounts.json | View secret |
| 34253507 | Triggered | Generic High Entropy Secret | bed18b9 | docker/devnet/seed-data/accounts.json | View secret |
| 34253508 | Triggered | Generic High Entropy Secret | bed18b9 | docker/devnet/seed-data/accounts.json | View secret |
| 34253509 | Triggered | Generic High Entropy Secret | bed18b9 | docker/devnet/seed-data/accounts.json | View secret |
| 34253510 | Triggered | Generic High Entropy Secret | bed18b9 | docker/devnet/seed-data/accounts.json | View secret |
| 34253511 | Triggered | Generic High Entropy Secret | bed18b9 | docker/devnet/seed-data/accounts.json | View secret |
🛠 Guidelines to remediate hardcoded secrets
- Understand the implications of revoking this secret by investigating where it is used in your code.
- Replace and store your secrets safely. Learn here the best practices.
- Revoke and rotate these secrets.
- If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.
To avoid such incidents in the future consider
- following these best practices for managing and storing secrets including API keys and other credentials
- install secret detection on pre-commit to catch secret before it leaves your machine and ease remediation.
🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.
Closes #55
Summary
Adds
.github/dependabot.ymlto enable automated dependency update PRs across all three package ecosystems in this repo, per #55.What's included
npmecosystem for/apinpmecosystem for/oraclecargoecosystem for/stellar-lendWhy
The project currently has no automated mechanism to surface dependency updates, including security patches in transitive dependencies. This config lets Dependabot open update PRs automatically so those can be reviewed and merged on a predictable cadence instead of going unnoticed.
Testing
This is a configuration-only change — no source code is modified. I validated the YAML locally before submitting. Once merged into the default branch, GitHub will pick up the config automatically and Dependabot will run its first scheduled scan.