Last reviewed: 2026-07-25
Dependency Advisor
Assess dependency policy quality and compliance scores, understand Advisor repository limits, and route score and policy changes by webhook.
Evaluate dependency decisions before release
Dependency Advisor calculates policy quality and compliance scores for repository dependencies. Use its score and policy context to identify where a dependency decision needs review; do not use a score as a certification or a release guarantee.
Availability and limits
Free organizations can use Advisor for one repository. Starter and higher plans can use it for unlimited repositories, subject to their other plan limits. Choose the correct organization before interpreting a repository score; similarly named repositories in another organization are separate records.
Category governance and stack trends
When no category-governance rules exist yet, generate a stack trends report (Reports) to see which root libraries teams already use per category. Select the libraries that should become organization whitelist rules (warning). Classification uses the seed catalog first, then an optional OVH model for unknown names (package name, ecosystem, description, and keywords only).
Operationalize changes
Subscribe an HTTPS receiver to score and policy events through webhooks if another system needs to react to a changed score or policy outcome. Deduplicate event deliveries and fetch the current repository context before taking action, because a score can change after a new commit or policy update.