Displays Dependabot vulnerability alerts of multiple repositories on a single page. Only vulnerabilities of repositories that your personal access token has access to will be displayed (restriction of GitHub's GraphQL API).
Hosted at dependabot-vuln-viewer.vercel.app.
Disclaimer: Your personal access token is, in theory, never sent to the server (the GraphQL API request is made by the browser). However, due to the magic behind Next.js and Apollo Client, I cannot guarantee it. Feel free to clone the repo and run it in local. Let me know if you know more than I do on this subject.
Can be any valid advanced search query string:
user:<a GitHub user>,repo:<repo owner>/<repo name>,- etc.,
- any combination of the above.
Two authentication methods are available (mutually exclusive):
-
GitHub OAuth Login (recommended): Click "Login with GitHub" in the top menu to authenticate via your GitHub account. Requires configuring a GitHub OAuth App (see below).
-
Personal Access Token: Enter a personal access token directly in the settings. Only the
reposcope is needed, orpublic_repoif you don't care about private repositories. Search settings are saved in browserlocalStorage, including the PAT, until you replace or clear them.
The app saves the search form values in browser localStorage and restores
them when you reload the page. This includes:
- the repository query
- the GitHub API URL
- the GitHub API token / PAT
- repos per request
- vulnerabilities per request
If you use the app on a shared machine, clear browser storage or remove the PAT from settings before you leave the device.
To enable the "Login with GitHub" option:
- Create a GitHub OAuth App in your GitHub settings.
- Set the Authorization callback URL to
<your-app-url>/api/auth/callback. - Configure the following environment variables:
where
GITHUB_OAUTH_CLIENT_ID=<your-client-id> GITHUB_OAUTH_CLIENT_SECRET=<your-client-secret> NEXT_PUBLIC_GITHUB_OAUTH_URL=<github-oauth-base-url><github-oauth-base-url>is the base URL of the GitHub OAuth endpoint (for example,https://github.com/login/oauth).
If these variables are not set, the OAuth option will not appear and the app will work as before using only personal access tokens.
git clone https://github.com/nyg/dependabot-vuln-viewer.git
cd dependabot-vuln-viewer
pnpm install
pnpm run dev # localhost:3000
pnpm run lint # runs eslint . --fix