AI / Dependabot Interview questions
What is Dependabot?
Dependabot is GitHub's built-in automated dependency management tool — it scans a repository's dependencies, checks them against the latest available versions and known security vulnerabilities, and automatically opens pull requests to update them, rather than developers having to manually track and bump dependency versions themselves.
# .github/dependabot.yml version: 2 updates: - package-ecosystem: "npm" directory: "/" schedule: interval: "weekly"
It runs natively within GitHub (no separate service to host or manage) and covers two related but distinct capabilities: keeping dependencies current with regular version updates, and specifically patching known security vulnerabilities as soon as they're identified in a project's dependency tree.
More Related questions...