Feedback: Dependency Scanning Auto-Remediation (Beta)
Everyone can contribute. Help move this issue forward while earning points, leveling up and collecting rewards.
Share your feedback on DS Auto-Remediation Beta
This issue collects feedback from users trying out Dependency Scanning Auto-Remediation during the 19.2 beta.
DS Auto-Remediation includes two capabilities:
- Automated dependency version bumps – GitLab monitors your projects for vulnerable dependencies and opens remediation MRs automatically.
- Agentic Breaking Change Resolution – When a bump MR's pipeline fails on a breaking change, GitLab Duo analyzes the errors, the dependency's changelog, and your code usage, then commits fixes to the same MR and re-runs the pipeline.
How to share feedback
Leave a comment on this issue with:
- What's working well
- What's not working as expected
- Ecosystems or package managers you'd like to see supported
- Any bugs or unexpected behavior (please include project type, language/ecosystem, and GitLab version)
Useful links
Edited by 🤖 GitLab Bot 🤖