GitHub Dependabot Posture Report
Delivers a weekly report on Dependabot coverage across a GitHub organization, what changed, and anything that needs attention.
What this agent does
This read-only agent checks the health of Dependabot across a GitHub organization every week. It finds active repositories where Dependabot alerts or security updates are off, and repositories whose Dependabot updates are failing. It summarizes the alerts that appeared, were fixed, or were dismissed since last week. It flags anything that needs an admin, such as a private registry Dependabot cannot reach or security update pull requests nobody has merged.
The challenge
Dependabot only works in repositories where it is set up correctly, and those settings change over time. A new repository starts with alerts off, a private registry credential expires, and update jobs fail without anyone noticing. Teams leave security update pull requests open for months. Admins find out when an auditor reports an old vulnerability.
The solution
The agent checks settings, update health, and alert activity across the organization in one pass each week and compares them with the previous week. It lists what changed and what someone needs to act on, with the fix for each item. Provides a weekly briefing an admin can read in a few minutes.
Workflow
- 01
Check coverage
Find active repositories where Dependabot alerts or security updates are off.
- 02
Check update health
Find failing Dependabot update jobs, unreachable private registries, and security update pull requests left open.
- 03
Check activity
Summarize alerts that appeared, were fixed, or were dismissed since last week.
- 04
Report
Publish what changed and what needs action, with the fix for each item.
Agent template
# GitHub Dependabot Posture Report
## Measurable outcomes
Every week, the admin knows which repositories Dependabot is not covering, what changed across the organization, and what needs action. Track covered and uncovered repositories and open action items on every run.
## Procedure
Once a week, check every active repository in the GitHub organization. List the repositories where Dependabot alerts or security updates are off. List the repositories whose Dependabot update jobs are failing, with the error, and call out any private registry Dependabot cannot reach. List security update pull requests open for more than two weeks, unless I set another window. Summarize the new Critical and High alerts, the alerts fixed, and the alerts dismissed since the last report, with who dismissed them and why. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine.
## Requirements
It needs GitHub read access to the organization's repositories, their security settings, and their Dependabot alerts and update jobs, and nothing more. It never changes repository settings, alerts, or pull requests. Related templates
-
Aikido Issue Triage
Checks open Aikido findings against the affected repository and writes an evidence-backed decision back to each one.
Vulnerability Management / Application Security 4 tools -
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Finding Triage
Writes an evidence-based judgment for each open Critical and High Security Hub CSPM finding, verifies it against the live resource, and suppresses the ones the checks prove are false positives.
Featured Vulnerability Management 2 tools