š„·š½ Main Branch: The One Where Security Is Free
Hiya friends,
GitHub shipped five new Dependabot ecosystems in a single week. And most public repos still donāt have CodeQL enabled. Letās fix both.
š¢ What Shipped
Dependabotās Big Week
GitHub dropped version update support for Bazel, Julia, OpenTofu, and Conda.
If youāre using any of these, Dependabot now watches your back.
Enable it now:
- Go to your repo ā Settings ā Security ā Advanced Security
- Click āEnableā next to Dependabot alerts
- Click āEnableā next to Dependabot security updates
- For version updates, add a
.github/dependabot.ymlconfig file to your repo:
version: 2
updates:
- package-ecosystem: "uv" # or npm, docker, etc.
directory: "/"
schedule:
interval: "weekly" # or "daily", "monthly", etc.
Done. Dependabot will open PRs when updates are available.
CodeQL: The Security Scanner Youāre Not Using
CodeQL is free for every public repository. Has been for years. It catches SQL injection, XSS, hardcoded credentials, and dozens of other vulnerabilities before they hit production.
Most repos donāt have it enabled. Thatās wild.
Enable it now:
- Go to your repo ā Settings ā Security ā Advanced Security
- Find āCode scanningā ā Click āSet upā ā āDefaultā
- Thatās it. Three clicks.
GitHub auto-detects your languages and runs CodeQL on every push and PR. No config file needed. Results show up in the Security tab and as PR annotations.
For private repos, youāll need GitHub Advanced Security. But if your code is public? This is free. Go turn it on.
šŗ What Iām watching
Sam Struan on ATS-friendly rĆ©sumĆ©s - ATS (Applicant Tracking Systems) is the software companies use to collect and organize job applications. Thereās a whole cottage industry selling āATS complianceā services, but Sam breaks it down in two minutes: itās mostly a scam. The real test is simple. Select all text in your PDF. If your contact info isnāt highlightable, it might not parse correctly. Thatās it. No magic.
Worth your time if: youāre job hunting or helping someone who is.
⨠This Week
It was a productive one. Wrapped up the week with Open Source Friday alongside Cassidy, Christina, and Kedasha. We donāt usually get to yap together on stream, so that was a treat. (Yes, the sunglasses were necessary.)

By the time you read this, Iāll be en route to Seattle for my teamās offsite. If you are local and wanna say hey, please DM.
Thatās it. Two features. Three clicks each. Go secure your repos.
With gratitude, Iāll see you next week,
Andrea
Subscribe to Main Branch
Join developers shipping real features. Every issue is a three-minute read packed with fundamentals you can apply today.
No spam. Unsubscribe anytime.