The repo tracks npm (package.json) and cargo (Cargo.toml, Cargo.lock) dependencies but has no .github/dependabot.yml, so neither ecosystem gets automated update or security checks.
Separately, dependabot alerts are disabled at the repo level. Enabling them in Settings > Code security would surface known vulnerabilities in the dependency tree.
Both are quick fixes. Happy to open a PR for the dependabot config.
Filed by the automated FreshJuice repo scan, run by Juicy (FreshJuice Bot app).
The repo tracks npm (package.json) and cargo (Cargo.toml, Cargo.lock) dependencies but has no .github/dependabot.yml, so neither ecosystem gets automated update or security checks.
Separately, dependabot alerts are disabled at the repo level. Enabling them in Settings > Code security would surface known vulnerabilities in the dependency tree.
Both are quick fixes. Happy to open a PR for the dependabot config.
Filed by the automated FreshJuice repo scan, run by Juicy (FreshJuice Bot app).