Dependabot Ecosystem Rule

Dependabot Ecosystem Rule Overview #

This rule detects package ecosystems that a repository depends on but does not configure in its Dependabot configuration (.github/dependabot.yaml / .github/dependabot.yml). It infers the required ecosystems from root-level lockfiles and from setup-* actions used in workflows, then reports each ecosystem that is not covered by a package-ecosystem entry.

The github-actions ecosystem is intentionally out of scope here; it is handled by the DependabotGitHubActionsRule.

Key Features #

  • Lockfile Signals: Infers ecosystems from lockfiles in the repository root.
  • Setup-action Signals: Infers ecosystems from setup-* actions in workflow steps.
  • Local-scan Only: Reads the local filesystem to locate lockfiles and the Dependabot config. The check is skipped in remote-scan mode.
  • Diagnose-only: Reports findings only; it does not auto-fix the Dependabot configuration.
  • Renovate Aware: When a Renovate configuration extends a broad preset (e.g. config:recommended), the check is skipped entirely. Otherwise only the ecosystems Renovate actually manages (via packageRules.matchManagers or enabledManagers) are treated as covered; warnings for other ecosystems still surface.
  • Precise Anchoring: Setup-action findings are anchored at the offending step; lockfile findings are reported at the top of the workflow file. When the same ecosystem is implied by both signals, the finding is deduplicated and keeps the precise step anchor.

Security and Reliability Impact #

Severity: Warning

Without a package-ecosystem entry, Dependabot will not open dependency-update pull requests for that ecosystem. Outdated dependencies accumulate known vulnerabilities, and major-version updates are not surfaced automatically. Configuring every ecosystem the repository actually uses keeps the supply chain patched.

Ecosystem Inference #

Root-level lockfiles #

FileEcosystem
package-lock.json, pnpm-lock.yaml, yarn.locknpm
go.sumgomod
Cargo.lockcargo
Gemfile.lockbundler
composer.lockcomposer
Pipfile.lock, poetry.lock, requirements.txtpip
pom.xmlmaven
build.gradle, build.gradle.kts, gradle.lockfilegradle

Only the repository root is scanned; lockfiles in subdirectories are not inferred.

Setup actions #

ActionEcosystem
actions/setup-nodenpm
actions/setup-gogomod
actions/setup-pythonpip
actions/setup-javamaven, gradle, or sbt
ruby/setup-rubybundler

actions/setup-java is ambiguous: it is considered satisfied when the Dependabot config contains any one of maven, gradle, or sbt.

Example Finding #

name: ci
on:
  push:
jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/setup-node@v4 # implies the npm ecosystem
        with:
          node-version: '20'

If .github/dependabot.yaml does not configure npm, the rule reports:

package ecosystem "npm" is used (detected from actions/setup-node) but not configured in dependabot.

Safe Configuration #

Add a matching package-ecosystem entry for every detected ecosystem:

version: 2
updates:
  - package-ecosystem: "npm"
    directory: "/"
    schedule:
      interval: "weekly"

Limitations #

  • Local-scan only; remote-scan mode skips the check.
  • Lockfiles are inferred from the repository root only (no recursive scan), so monorepo dependencies nested in subdirectories are not detected.
  • Matching is based on the presence of a package-ecosystem; the Dependabot directory value is not cross-checked.
  • The Renovate skip is best-effort: a recognized broad preset skips the check globally; otherwise only ecosystems Renovate actually manages (matched via packageRules.matchManagers or enabledManagers) are treated as covered, and warnings for the rest still surface.
  • The rule is diagnose-only and does not provide an auto-fix.