Files
llm-wiki/raw/official-docs/dependabot-security-updates-gradle-official.md
T

96 lines
8.9 KiB
Markdown

---
title: "About Dependabot Security Updates — GitHub Official Docs"
source_type: official-doc
url: https://docs.github.com/en/code-security/concepts/supply-chain-security/about-dependabot-security-updates
archive_url:
related_branches: [feature-dependency-vulnerability-management-contract]
related_projects: []
tags: [official-doc, ca-tmpl, security, ci-cd]
created: 2026-06-15
---
# About Dependabot Security Updates — GitHub Official Docs
> Layer: `raw/` — 외부 자료(공식 문서)의 **원문 발췌·출처 기록**.
> 검증된 요약은 `/ingest` 후 `wiki/concepts/`에 별도 작성. 원본은 raw에 영구 보관.
## Parent / 활용 branch
| Branch | 이 자료가 정당화하는 결정 |
|---|---|
| [[raw/branch-notes/feature-dependency-vulnerability-management-contract]] | Dependabot은 조건부(조직 표준이거나 단순 Gradle 구조) 허용. Dependabot security updates의 정의와 grouping 동작(생태계 단위 묶음, 버전 업데이트와 혼합 불가)이 근거. |
## 출처 / Source
- 원본 URL: https://docs.github.com/en/code-security/concepts/supply-chain-security/about-dependabot-security-updates
- 아카이브 URL: (미등록)
- 저자 / 조직: GitHub, Inc.
- 발행일: (GitHub Docs — 지속 갱신 문서)
- 마지막 확인일: 2026-06-15
## 왜 저장했는지 / Why archived
Dependabot security updates의 공식 정의, security vs version updates 구분, grouped security updates 동작 제약(생태계 간 묶음 불가 / 버전 업데이트와 묶음 불가)을 verbatim 으로 확보하기 위해 보관. `feature-dependency-vulnerability-management-contract` 브랜치의 "Dependabot 조건부 허용" 결정의 기반 근거.
## 핵심 인용 / Key quotes (verbatim, 3~5문장)
> [§About Dependabot security updates — bullet list] "*Dependabot security updates* are automated pull requests that help you update dependencies with known vulnerabilities."
> (fetched text line 31)
> [§About Dependabot security updates — bullet list] "*Dependabot version updates* are automated pull requests that keep your dependencies updated, even when they don't have any vulnerabilities. To check the status of version updates, navigate to the **Insights** tab of your repository, then select **Dependency Graph**, and Dependabot."
> (fetched text line 32)
> [§About grouped security updates — paragraph 1] "To further reduce the number of pull requests you may be seeing, you can enable grouped security updates to group sets of dependencies together (per package ecosystem). Dependabot then raises a single pull request to update as many vulnerable dependencies as possible in the group to secure versions at the same time."
> (fetched text line 42)
> [§About grouped security updates — paragraph 2] "For security updates, Dependabot will only group dependencies from different directories per ecosystem under certain conditions and configurations. Dependabot **will not** group dependencies from different package ecosystems together, and it **will not** group security updates with version updates."
> (fetched text line 44)
> [§About Dependabot security updates — paragraph 5] "However, security updates are triggered only for dependencies that are specified in a manifest or lock file."
> (fetched text line 23, within longer sentence)
## Claims Extracted / 추출된 주장
| Claim ID | Claim (이 자료가 직접 말하는 것) | Evidence quote | Strength | Applies to | Does not prove |
|---|---|---|---|---|---|
| C1 | Dependabot security updates는 알려진 취약점이 있는 의존성을 업데이트하는 자동 PR이다 | [§About Dependabot security updates] "*Dependabot security updates* are automated pull requests that help you update dependencies with known vulnerabilities." | `official-vendor-doc` | GitHub Dependabot이 활성화된 모든 저장소 | 특정 언어/빌드툴(Gradle 등)에서 실제로 동작함을 보장하지 않음. 지원 생태계 목록(별도 페이지) 확인 필요 |
| C2 | Dependabot version updates는 취약점 없이도 의존성을 최신으로 유지하는 별도 기능이다 | [§About Dependabot security updates] "*Dependabot version updates* are automated pull requests that keep your dependencies updated, even when they don't have any vulnerabilities." | `official-vendor-doc` | Dependabot version updates를 활성화한 저장소 | security updates와 version updates가 동시에 활성화될 때의 상호작용 세부 동작은 별도 확인 필요 |
| C3 | Grouped security updates는 생태계(package ecosystem) 단위로 묶어 단일 PR을 발행한다 | [§About grouped security updates] "you can enable grouped security updates to group sets of dependencies together (per package ecosystem). Dependabot then raises a single pull request to update as many vulnerable dependencies as possible in the group to secure versions at the same time." | `official-vendor-doc` | grouped security updates를 활성화한 저장소 | 어떤 저장소/생태계가 grouping을 지원하는지 — 지원 생태계 별도 페이지 확인 필요 |
| C4 | Dependabot은 서로 다른 package ecosystem의 의존성을 하나의 그룹으로 묶지 않으며, security updates와 version updates를 함께 묶지 않는다 | [§About grouped security updates] "Dependabot **will not** group dependencies from different package ecosystems together, and it **will not** group security updates with version updates." | `official-vendor-doc` | grouped security updates 사용 시 항상 적용되는 불변 제약 | 이 제약이 미래 GitHub 정책 변경으로 바뀔 수 없다는 보장은 아님 |
| C5 | Security updates는 manifest 또는 lock file에 명시된 의존성에 대해서만 트리거된다 | [§About Dependabot security updates] "security updates are triggered only for dependencies that are specified in a manifest or lock file." | `official-vendor-doc` | Dependabot security updates를 사용하는 모든 저장소 | transitive/indirect 의존성에 대한 PR 생성 여부 (ecosystem별로 다름 — npm은 예외적으로 parent까지 업데이트 가능, 별도 note box 참조) |
### NOT supported by this page
- **native auto-merge in dependabot.yml**: 이 페이지에는 `auto-merge` 키워드가 전혀 등장하지 않는다. auto-merge 동작 여부는 별도 페이지(`Configuring Dependabot security updates` 또는 GitHub branch protection / merge queue 문서)에서 확인해야 한다. 이 자료만으로는 "dependabot.yml에 native auto-merge 설정이 없다"고도, "있다"고도 증명 불가 — `NEEDS_CONFIRMATION`.
- **Gradle 생태계의 구체적 지원 여부**: 이 페이지는 지원 생태계를 별도 링크(`Dependabot supported ecosystems and repositories`)로 위임. Gradle이 지원됨을 이 페이지에서 직접 확인할 수 없다.
## Usage Boundaries / 적용 경계
- 이 자료가 직접 증명하는 것:
- `C1`: GitHub Dependabot security updates의 공식 정의
- `C2`: security updates vs version updates의 공식 구분
- `C3`: grouped security updates의 동작 방식 (생태계 단위, 단일 PR)
- `C4`: grouped security updates의 불변 제약 (cross-ecosystem 묶음 불가, version updates와 혼합 불가)
- `C5`: security updates 트리거 조건 (manifest/lock file 명시 의존성 한정)
- 이 자료가 증명하지 않는 것:
- Gradle 생태계에서의 실제 지원 여부 (별도 페이지 확인 필요)
- native auto-merge 설정의 존재 여부 (이 페이지에서 언급 없음)
- transitive dependency 처리의 일반 규칙 (npm은 예외, 다른 생태계는 제한적)
- 내 프로젝트에 적용하려면 추가 확인이 필요한 것:
- ca-tmpl Gradle 프로젝트가 Dependabot 지원 생태계 목록에 포함되는지
- grouped security updates 활성화 시 실제 PR 생성 패턴 (단순 Gradle 구조 가정 검증)
## 메모 / Notes
- auto-merge 관련: 이 페이지에 없으므로 날조 금지. "GitHub Actions workflow + `gh pr merge --auto`" 또는 별도 branch protection auto-merge 설정으로 구현하는 패턴이 일반적이나, 그 근거는 별도 문서에서 확보 필요.
- Gradle grouping 실제 동작: `dependabot.yml``groups:` 키를 추가하면 per-ecosystem 묶음 가능 — 단 상세 설정 방법은 `Configuring Dependabot security updates` 페이지 참조 필요.
- 추가로 봐야 할 동일 출처 페이지:
- `https://docs.github.com/en/code-security/dependabot/dependabot-security-updates/configuring-dependabot-security-updates` (설정 세부)
- `https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/about-dependabot-version-updates` (version updates 비교)
- `https://docs.github.com/en/code-security/dependabot/working-with-dependabot/dependabot-supported-ecosystems-and-repositories` (Gradle 지원 여부)
## Related / 관련
- 같은 주제 다른 official-doc / company-tech-blog: (미등록 — 추가 시 여기 링크)
- 이 자료를 인용한 wiki 요약: (미생성 — `/ingest``wiki/concepts/dependabot-security-updates.md` 후보)