Why
Part of the enterprise-grade supply-chain story. Manual NuGet dependency tracking is a non-starter for a project with ~30 direct deps + hundreds of transitives, and the recent CVE-2026-33116 / Scriban incident showed vulnerable deps land on develop and sit until someone notices.
Scope
- Decide: Dependabot vs Renovate. Dependabot is simpler and GitHub-native; Renovate is more powerful (grouping, schedule, custom managers) but needs an app install. Default: Dependabot for speed-to-value; revisit Renovate if grouping/scheduling becomes a problem.
- Configure for: nuget (
Directory.Packages.props), github-actions (.github/workflows/*.yml), and the dotnet SDK version (global.json).
- Schedule: weekly bundled PRs by ecosystem; daily for security advisories.
- Auto-merge: not initially. Triage manually until the CI release pipeline is trustworthy.
Done when
Related: enterprise CI/CD positioning.
Why
Part of the enterprise-grade supply-chain story. Manual NuGet dependency tracking is a non-starter for a project with ~30 direct deps + hundreds of transitives, and the recent CVE-2026-33116 / Scriban incident showed vulnerable deps land on
developand sit until someone notices.Scope
Directory.Packages.props), github-actions (.github/workflows/*.yml), and the dotnet SDK version (global.json).Done when
.github/dependabot.yml(orrenovate.json) committedRelated: enterprise CI/CD positioning.