{"id":44349941,"url":"https://github.com/timothywarner-org/globomantics-robot-fleet","last_synced_at":"2026-02-11T14:36:40.452Z","repository":{"id":297512065,"uuid":"996119324","full_name":"timothywarner-org/globomantics-robot-fleet","owner":"timothywarner-org","description":"🤖 Globomantics Robot Fleet Manager - Educational demo with vulnerable dependencies for GitHub Advanced Security training. Tim Warner's Pluralsight Dependency Review course. Learn more: https://pluralsight.com","archived":false,"fork":false,"pushed_at":"2026-02-03T16:52:50.000Z","size":1269,"stargazers_count":0,"open_issues_count":38,"forks_count":1,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-02-04T06:24:27.734Z","etag":null,"topics":["dependabot","dependency-review","dependency-scanning","educational-demo","github-advanced-security","npm-audit","pluralsight","security-training","supply-chain-security","vulnerable-dependencies"],"latest_commit_sha":null,"homepage":null,"language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/timothywarner-org.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null},"funding":{"github":["your_github_username"],"patreon":["your_patreon_username"],"open_collective":["your_open_collective_username"],"ko_fi":["your_ko_fi_username"],"tidelift":["package_name"],"community_bridge":["your_community_bridge_project_name"],"liberapay":["your_liberapay_username"],"issuehunt":["your_issuehunt_username"],"otechie":["your_otechie_username"],"custom":["https://www.example.com/donate"]}},"created_at":"2025-06-04T13:36:37.000Z","updated_at":"2026-02-03T16:20:36.000Z","dependencies_parsed_at":"2025-07-27T12:02:41.045Z","dependency_job_id":"0ba329a1-31ce-4394-a675-8c46500be15c","html_url":"https://github.com/timothywarner-org/globomantics-robot-fleet","commit_stats":null,"previous_names":["timothywarner-org/globomantics-robot-fleet"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/timothywarner-org/globomantics-robot-fleet","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/timothywarner-org%2Fglobomantics-robot-fleet","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/timothywarner-org%2Fglobomantics-robot-fleet/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/timothywarner-org%2Fglobomantics-robot-fleet/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/timothywarner-org%2Fglobomantics-robot-fleet/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/timothywarner-org","download_url":"https://codeload.github.com/timothywarner-org/globomantics-robot-fleet/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/timothywarner-org%2Fglobomantics-robot-fleet/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29335276,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-11T14:34:07.188Z","status":"ssl_error","status_checked_at":"2026-02-11T14:34:06.809Z","response_time":97,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["dependabot","dependency-review","dependency-scanning","educational-demo","github-advanced-security","npm-audit","pluralsight","security-training","supply-chain-security","vulnerable-dependencies"],"created_at":"2026-02-11T14:36:40.334Z","updated_at":"2026-02-11T14:36:40.441Z","avatar_url":"https://github.com/timothywarner-org.png","language":"Shell","funding_links":["https://github.com/sponsors/your_github_username","https://patreon.com/[\"your_patreon_username\"]","https://opencollective.com/[\"your_open_collective_username\"]","https://ko-fi.com/[\"your_ko_fi_username\"]","https://tidelift.com/funding/github/[\"package_name\"]","https://funding.communitybridge.org/projects/[\"your_community_bridge_project_name\"]","https://liberapay.com/[\"your_liberapay_username\"]","https://issuehunt.io/r/[\"your_issuehunt_username\"]","https://otechie.com/[\"your_otechie_username\"]","https://www.example.com/donate"],"categories":[],"sub_categories":[],"readme":"# Globomantics Robot Fleet Manager V2\r\n\r\n**Enterprise Security Demo - GitHub Advanced Security Course**\r\n\r\nThis is a fictional internal business application for Globomantics Robotics Corporation's robot fleet management system. This application demonstrates **production-grade GitHub Advanced Security** features used by Fortune 500 companies.\r\n\r\n## 🎯 Module 3: Automated Dependency Management\r\n\r\nThis repository showcases the **complete enterprise security pipeline** that 80% of production teams use in the real world:\r\n\r\n### 🔒 Enterprise Security Features\r\n\r\n✅ **Dependency Review Workflow** (`.github/workflows/dependency.review.yml`)\r\n- Advanced vulnerability filtering (moderate severity threshold)\r\n- License compliance checking (allow/deny lists)\r\n- Automated security reporting in PR comments\r\n- Multi-trigger event handling for efficiency\r\n\r\n✅ **Enterprise Dependabot Configuration** (`.github/dependabot.yml`)\r\n- Security-first: Daily vulnerability scans\r\n- Noise reduction: Grouped updates by risk level\r\n- Team workflow: Auto-assign + Copilot reviews\r\n- Smart labeling: `dependencies`, `security`, `automated`\r\n- Risk management: Ignore breaking changes for critical packages\r\n\r\n✅ **Production Security Labels**\r\n- 🔵 `dependencies` - All dependency updates\r\n- 🔴 `security` - High-priority security fixes\r\n- 🟣 `automated` - Bot-generated PRs\r\n\r\n## ⚠️ IMPORTANT - Educational Use Only\r\n\r\nThis application contains **intentionally vulnerable dependencies** for security training purposes. **DO NOT use in production environments.**\r\n\r\n## Vulnerable Dependencies (For Class Demos)\r\n\r\nThe following dependencies contain known vulnerabilities for demonstration purposes:\r\n\r\n### Original Vulnerable Packages\r\n- `express` 4.17.1 - Various security vulnerabilities\r\n- `lodash` 4.17.20 - Prototype pollution vulnerabilities\r\n- `axios` 0.21.1 - Server-side request forgery vulnerabilities\r\n- `ejs` 3.1.6 - Code injection vulnerabilities\r\n- `moment` 2.29.1 - ReDoS vulnerabilities (deprecated)\r\n\r\n### Added for Enhanced Demo\r\n- `debug` 2.6.8 - Known security issues\r\n- `serialize-javascript` 3.0.0 - XSS vulnerabilities\r\n- `handlebars` 4.0.0 - Prototype pollution\r\n- `ws` 5.2.0 - DoS vulnerabilities\r\n- `tar` 4.4.8 - Path traversal issues\r\n\r\n## 🚀 Quick Start\r\n\r\n```bash\r\nnpm install\r\nnpm start\r\n```\r\n\r\nVisit `http://localhost:3000` to access the Globomantics Robot Fleet Manager.\r\n\r\n## 📊 Demo Workflow\r\n\r\n1. **Branch Protection** - Main branch protected with required reviews\r\n2. **Dependency Review** - Automated security scanning on PRs\r\n3. **Vulnerability Detection** - 34+ known vulnerabilities flagged\r\n4. **Enterprise Dependabot** - Automated dependency management\r\n5. **Security Dashboard** - Complete visibility into dependency risks\r\n\r\n## 🎓 Learning Objectives\r\n\r\nThis demonstration shows enterprise teams how to:\r\n\r\n### Security-First Development\r\n- Implement **daily vulnerability scanning**\r\n- Configure **license compliance** checking\r\n- Set up **automated security reporting**\r\n\r\n### Team Workflow Integration\r\n- **Smart PR labeling** for security priorities\r\n- **Grouped dependency updates** to reduce noise\r\n- **Automated reviewer assignment** (including Copilot)\r\n\r\n### Risk Management\r\n- **Severity thresholds** for production environments\r\n- **Breaking change protection** for critical packages\r\n- **Vendor restrictions** for trusted registries only\r\n\r\n### Production Pipeline\r\n- **Multi-ecosystem support** (NPM + GitHub Actions)\r\n- **Conventional commit messages** for automation\r\n- **Enterprise permission models** (least privilege)\r\n\r\n## 🏢 Enterprise Standards Demonstrated\r\n\r\nThis setup represents **real-world production practices** used by:\r\n- Microsoft Azure DevOps teams\r\n- GitHub's own internal security workflows\r\n- Fortune 500 dependency management strategies\r\n- Open source project security standards\r\n\r\n---\r\n\r\n**Course:** GitHub Advanced Security - Module 3\r\n**Instructor:** Tim Warner (@timothywarner-org)\r\n**Platform:** Pluralsight\r\n\r\n*Globomantics Robotics Corporation - Internal Use Only*\r\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftimothywarner-org%2Fglobomantics-robot-fleet","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ftimothywarner-org%2Fglobomantics-robot-fleet","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftimothywarner-org%2Fglobomantics-robot-fleet/lists"}