Skip to content

Which problem does Dependency-Track solve that Dependabot doesn't solve already? #1519

Answered by msymons
AbdelHajou asked this question in Q&A
Discussion options

You must be logged in to vote

Further to what @ruckc has said: whilst Dependabot will take care of upgrading a component when an upgrade is available it won't help when there is no fix available. Additionally, it won't help when you have a transitive dependency that has a vulnerability if you are not managing that dependency.

Also, in practice one will often end up "teaching" Dependendabot and (say) allowing only patch and minor upgrades for a particular component where one is not yet ready for a major upgrade (ie, cannot upgrade client for server X until server X is itself upgraded). But such decisions have consequences... one might have no vulnerability exposure today and half a dozen vulnerabilities within a short …

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by AbdelHajou
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants