Automic VaultAutomic Vault

brew

dependabot mit Homebrew installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für dependabot in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install dependabot

local Homebrew formula metadata

Überblick

Paketzusammenfassung

Tool for testing and debugging Dependabot update jobs

Befehle und Aliase

  • dependabot

Verlauf

Projektgeschichte und Nutzung

Dependabot CLI is the command-line companion for running Dependabot update jobs outside the hosted GitHub workflow. It is aimed less at end users casually enabling dependency updates and more at maintainers, security engineers, and package ecosystem developers who need to reproduce, debug, or smoke-test the exact update jobs that Dependabot runs.

Projektgeschichte

The CLI repository was created under the official Dependabot GitHub organization in 2022. Its README describes a Go command that runs Dependabot jobs, pulls the updater and proxy container images, and records the pull-request operations that a hosted Dependabot run would normally perform.

The tool is closely tied to Dependabot's broader configuration model: the same package ecosystem names, repository paths, registry credentials, and update-job concepts show up in both CLI job files and GitHub's official dependabot.yml documentation.

Adoptionsgeschichte

Adoption is mainly among people who already operate Dependabot at scale. The README points users to Go installation, GitHub releases, and Homebrew, which made the tool easy to reach from developer laptops and CI debugging sessions without building Dependabot internals by hand.

Wie es verwendet wird

Typical usage is to run `dependabot update` for a package ecosystem and repository, or to pass a YAML job description for security-update and private-registry cases. The CLI can pass tokens from environment variables into the proxy so that the updater can access GitHub APIs and package registries without directly receiving secrets.

Warum Paket-Nerds sich dafür interessieren

For package nerds, Dependabot CLI is interesting because it exposes the machinery behind automated dependency PRs: ecosystem identifiers, manifest directory selection, registry credentials, update strategies, and the split between updater containers and a credential-injecting proxy.

Zeitleiste

  • 2022: Official dependabot/cli repository created.
  • 2022: README examples documented `dependabot update` and smoke-test workflows.
  • 2026: GitHub Docs continue to document dependabot.yml as the primary configuration surface for Dependabot.

Related projects

  • Dependabot CLI depends conceptually on dependabot-core for package ecosystem behavior and on GitHub's dependabot.yml configuration model for hosted repository updates.

Sicherheitslage

Noch keine Protected-Tool-Abdeckung gefunden

Für dependabot wurde kein passendes lokales Secret-Handling-Manifest gefunden. Nucleus-Paketmetadaten bleiben hier veröffentlicht, damit künftige Abdeckung eine stabile Paket-URL hat.

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 6 Plattformziele verfügbar.
  • Build-Metadaten listen 1 Build-Abhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
.github/dependabot.yml

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
dependabotcliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-25
Manager-Version1.91.0
Manager aktualisiert2026-06-29
lokale DatenOK
Upstreamaktuell
neueste erkannte Versionv1.91.0

https://github.com/dependabot/cli

  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:dependabot
Version1.91.0
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/dependabot
Homepagehttps://github.com/dependabot/cli
Repositoryhttps://github.com/dependabot/cli
Upstream-Dokumentationhttps://github.com/dependabot/cli#readme
LizenzMIT
Quellarchivhttps://github.com/dependabot/cli/archive/refs/tags/v1.91.0.tar.gz
Zuletzt aktualisiert2026-06-29T20:51:51Z
Pulseupdated
Build-Abhängigkeitengo
Bottleverfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namedependabot
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • package relationship graph
  • package version freshness
  • package-page enrichment