Dependabot now supports security alerts and automated pull requests for uv dependencies. When vulnerabilities are detected in projects using uv (a fast Python package manager), Dependabot can automatically create security alerts and open PRs to update to secure versions, extending GitHub's automated dependency security capabilities to the uv ecosystem.

1m read timeFrom github.blog
Post cover image

Sort: