List Dependabot security alerts for a GitHub repository to identify and manage vulnerable dependencies. Supports filtering by state, severity, package, and ecosystem.
Configure the default repository access level for Dependabot across an organization. Assign permissions for Dependabot to access repositories by default.
Enables AI assistants to monitor GitHub repository health by calculating health scores, fetching repository metadata, analyzing Dependabot alerts, checking CI/CD status, and retrieving code scanning alerts.
Fetch Dependabot alerts for a GitHub repository to uncover vulnerable package dependencies. Pinpoint security risks in npm, pip, and other ecosystems before they impact your project.
Assess overall GitHub repository health by calculating a 0-100 score and A-F grade across CI, security, community, maintenance, and freshness. Includes improvement suggestions and historical trend data.
Installs missing CI/CD, security, dependabot, or maintenance files from a starter into an existing repo. Default dry-run previews the file plan; set dry_run false to apply only necessary changes.
Install authentication, payment, storage, production, and DevOps plugins into a BackGen project. Each plugin injects source files, registers routes, and updates dependencies.
Run a comprehensive security scan on a repository using multiple parallel scanners to detect vulnerabilities, secrets, and dependency CVEs, and receive a deduplicated severity-ranked report.
Compare two package versions to receive a structured upgrade analysis: semver classification, breaking changes, security advisories, migration guides, and a recommendation.
Retrieve GitHub API metadata including IP ranges, SSH key fingerprints, public keys, and password auth status to support firewall allowlisting, SSH host verification, and infrastructure automation.
Batch-analyze up to 50 package upgrades to get a unified risk report ranked by security, caution, review, likely-safe, and safe, with breaking changes and CVEs.
Audit a local repository for security CI hygiene, checking gitleaks, CodeQL, dependency audits, license compliance, Dependabot, and secret scanning. Ensures alignment with the Starter Series quality bar.