GitHub Dependency Release Monitor avatar

GitHub Dependency Release Monitor

Pricing

from $3.00 / 1,000 results

Go to Apify Store
GitHub Dependency Release Monitor

GitHub Dependency Release Monitor

Monitor public GitHub repositories for latest-release changes and dependency-manifest changes against caller-supplied baselines.

Pricing

from $3.00 / 1,000 results

Rating

0.0

(0)

Developer

coolinbex

coolinbex

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

4 days ago

Last modified

Categories

Share

Production-oriented Apify Actor that checks public GitHub repositories for latest-release changes and dependency-manifest changes against user-supplied baselines.

Supported manifests

package.json, package-lock.json, npm-shrinkwrap.json, requirements.txt, pyproject.toml, Pipfile, go.mod, Cargo.toml, and composer.json. Parsing is intentionally conservative: lockfile formats and arbitrary build-generated manifests may not be fully represented. Unsupported files are skipped and parser/request problems remain visible as partial or error records.

Input example

{
"repositories": ["https://github.com/apify/apify-cli", "nodejs/node"],
"baselines": {
"nodejs/node": {
"releaseTag": "v22.0.0",
"manifests": {"package.json": {"dependencies": {"semver": "^7.6.0"}}}
}
},
"includeUnchanged": true,
"maxRepositories": 20
}

A baseline is optional. Without one, the Actor reports current state but cannot infer historical change. Baselines are supplied by the caller; the Actor does not persist state between runs. Use a stable baseline snapshot (including manifest hashes where available) for reliable comparisons.

GitHub limits and security

The Actor uses public REST endpoints and requires no credential by default. Unauthenticated GitHub API traffic is rate-limited (typically 60 requests/hour per source IP), and each repository can require one release request plus several manifest requests. Keep repository and manifest limits bounded and pace requests. A GitHub fine-grained token may optionally be supplied as a secret input to improve rate limits; it is only sent in the Authorization header, never logged, stored in records, or included in the summary. Do not use a token you do not have permission to use.

The Actor emits stable records with ok, partial, or error status and a summary key-value record. Partial repository results are retained rather than silently discarded. includeUnchanged: false filters successful unchanged records, but failures and partial records remain visible.

Local validation

npm install
npm test
npm run check

No request is made during the unit tests; GitHub calls are mocked. The Actor does not push, schedule, or publish itself.