Automated security updates (formerly Dependabot and automated security fixes) are now generally available in all public repositories on GitHub. After a popular debut at Satellite 2019, more than 3.5 million active repositories have the feature enabled and receive automated pull requests that update them to the nearest non-vulnerable dependency versions. Thanks to all of our beta testers and Dependabot users for your feedback and support.
GitHub Security Advisories now out of beta and automatic CVE requests
GitHub Security Advisories, which launched in beta earlier this year, are now generally available. And we’ve made some exciting changes based on feedback from maintainers. First, we’ve added the ability to automatically request a CVE identifier for any Security Advisory. We’ve also refined the process of creating and publishing a Security Advisory, so that it’s clearer when the advisory will become public and easier to provide the information needed to power automatic dependency updates via the GitHub Advisory Database.