Skip to content

project

Dependabot

GitHub's built-in bot that scans repositories for outdated or vulnerable dependencies, flags security alerts, and opens pull requests to update them.

Known aliases

  • Dependabot Alerts
  • dependabot[bot]
  • Dependabot version updates

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

Node 26.8.2 bumps OpenSSL, undici and npm inside the runtime

Upgrading a Node 26 binary also upgrades the TLS library, the bundled HTTP client and the package manager. The 26.8.2 changelog names OpenSSL 3.5.8, undici 8.10.2 and npm 11.19.1 among its dependency commits.

Publishers:nodejs.org

Reality

Evidence78
Adoption20
Hype gap−8
Incentives32
Confidence70