Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Provide list or dashboard of Dependabot findings per team #9599

Closed
1 task done
alekgosk opened this issue Apr 24, 2024 · 1 comment
Closed
1 task done

Provide list or dashboard of Dependabot findings per team #9599

alekgosk opened this issue Apr 24, 2024 · 1 comment
Labels
L: git:submodules Git submodules L: javascript L: ruby:bundler RubyGems via bundler T: feature-request Requests for new features

Comments

@alekgosk
Copy link

alekgosk commented Apr 24, 2024

Is there an existing issue for this?

  • I have searched the existing issues

Feature description

Hi,

I know Dependabot currently provides an option to see open Security Advisories for a particular GitHub repository. I also know it's possible to group them per ecosystem (for example Ruby bundler, javascript, etc.)

For us however, it would be super beneficial to group open Security Advisories per teams within Github.

For context - we are currently looking into improving our Operational Excellence and want to have a generic dashboard within DataDog, that includes open security vulnerabilities. We want to have those operational excellence dashboards per team, with their own business metrics but also having some generic bits all teams should have - like open Security Advisories being one of them.

Having a link for example like this, that we could put into our DataDog dashboard:

https://github.com/[organisation]/[team]/security/dependabot

with a list of open Dependabot issues grouped per team in Github, would be greatly beneficial!

I hope what I wrote and described makes sense, please let me know if further clarification is needed!

@alekgosk alekgosk added the T: feature-request Requests for new features label Apr 24, 2024
@github-actions github-actions bot added L: git:submodules Git submodules L: javascript L: ruby:bundler RubyGems via bundler labels Apr 24, 2024
@alekgosk alekgosk changed the title Provide list or dashboard of security vulnerabilities per team Provide list or dashboard of Dependabot findings per team Apr 24, 2024
@jeffwidman
Copy link
Member

Great feedback, but this is the wrong place to post this request... this shows the better place to request it: https://github.com/dependabot/dependabot-core?tab=readme-ov-file#dont-file-issues-about-security-alerts-or-dependency-graph

See also the one exception we've made so folks have a centralized place to discuss:

@jeffwidman jeffwidman closed this as not planned Won't fix, can't repro, duplicate, stale May 1, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
L: git:submodules Git submodules L: javascript L: ruby:bundler RubyGems via bundler T: feature-request Requests for new features
Projects
Status: Done
Development

No branches or pull requests

2 participants