It’s time to be clear about the very significant limits of Dependabot.
It’s time to be clear about the very significant limits of Dependabot.
@manicode Yep. Dependsbot is not comprehensive enough. Users and customers have been noting this for a while and part of the reasons why they find Snyk more helpful and actionable
@manicode Not sure how much of this claim is true , i assumed , they use pom files for java maven instead of lock files , because we do get lot of alerts based on libraries we use, is there a list of languages it does not do well ? @dependabot is it true ?
@manicode Totally agree, I know you're on team "worse than nothing," but I always made sure to tell people it's only good for the compliance checkbox.
@manicode Currently, Dependabot can't scan gradle build files 😀
@manicode Dependabot is code quality not SCA; doesn’t look at compiled code