Recurring notification that a repository's dependencies have newer releases upstream, for any user, without requiring a runner or per-repo scripting.
Approach: a background worker in the daemon reads the manifests from the default branch, queries the ecosystem registry for the current release, and maintains one issue per repository — opened when something falls behind, rewritten when the set changes, closed when nothing is behind. Opt-in per repository, since checking a private repo tells a public registry what it depends on.
Ecosystems: go.mod (proxy.golang.org), package.json + package-lock.json (npm), Cargo.toml + Cargo.lock (crates.io), requirements.txt + pyproject.toml (PyPI).
Generating an MR for an update is deliberately out of scope here. Doing it in the daemon means reimplementing dependency resolution per ecosystem; doing it through the runner means giving the update job the runner's ambient credentials. Worth deciding separately once the reports have been running.
closed by commit 6c97fd8119 by cmc: Report dependencies that have fallen behind upstream
2026-08-31 03:37 UTC