List Dependabot security alerts for a GitHub repository to identify and manage vulnerable dependencies. Supports filtering by state, severity, package, and ecosystem.
Configure the default repository access level for Dependabot across an organization. Assign permissions for Dependabot to access repositories by default.
This server integrates with GitHub Advanced Security to load security alerts and bring it into your context. Supports Dependabot Security Alerts, Secret Scanning Alerts, Code Security Alerts
Installs missing CI/CD, security, dependabot, or maintenance files from a starter into an existing repo. Default dry-run previews the file plan; set dry_run false to apply only necessary changes.
Install authentication, payment, storage, production, and DevOps plugins into a BackGen project. Each plugin injects source files, registers routes, and updates dependencies.
Analyze upgrading a single npm or PyPI package from one version to another, returning semver class, breaking changes, security fixes, migration guides, and a clear upgrade recommendation.
Analyzes multiple package upgrades simultaneously to generate a risk-ranked report identifying security fixes, breaking changes, and recommendations from caution to safe.
Run a comprehensive security scan on a repository using multiple parallel scanners to detect vulnerabilities, secrets, and dependency CVEs, and receive a deduplicated severity-ranked report.
Retrieve GitHub API metadata including IP ranges, SSH key fingerprints, public keys, and password auth status to support firewall allowlisting, SSH host verification, and infrastructure automation.
Audit a local repository for security CI hygiene, checking gitleaks, CodeQL, dependency audits, license compliance, Dependabot, and secret scanning. Ensures alignment with the Starter Series quality bar.
Retrieve current GitHub Dependabot alerts for a repository to view and manage security vulnerabilities. Input repository owner and name to access detailed alerts.