Skip to content

Latest commit

 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Dependency Watch

Your own copy of the Ambush bot that tells you when a security advisory touches a repo you watch, with the fix.

It listens to Ambush's Package Security Advisories stream, reads what each of your repos depends on from GitHub's dependency graph, checks the exact version with OSV.dev, and posts one message to Slack when a repo is hit.

Setup

The steps are in AGENTS.md. Follow them yourself, or hand them to a coding agent like Claude Code or Cursor: "read AGENTS.md and follow it". The same guide is on the bot's page in Ambush: Explore → Dependency Watch.

bun install
cp .env.example .env   # then fill it in
bun run check          # what GitHub says each repo uses
bun run dev            # listens on :3000/ambush

What each file does, and every setting, is in AGENTS.md.

License

MIT

About

An Ambush bot you run yourself: hears about the vulnerabilities Dependabot can't see yet, checks your repos' versions with OSV.dev, and tells you the fix.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages