---
title: "GitHub's Latest Dependency Graph Update: What Developers Need to Know"
description: latest update to GitHub's dependency graph, enhancing SBOM generation with precise package URLs
image: https://codenotary.com/hubfs/CN-Assets%20(77).png
---

**$ protect --distro linux --machines 25 --free**

[Start now](https://apps.codenotary.com/linux)

[![cn-logo-black-nobg](https://codenotary.com/hubfs/cn-logo-black-nobg.svg)](https://codenotary.com/)

- Product
  
  #### [![AgentMon Start](https://codenotary.com/hubfs/AgentMon%20Start.svg) **AgentMon Start** Organization-wide AI agent spend, security and device fleet TRY NOW →](https://apps.codenotary.com/agentmon-start)
  
  #### [![AgentMon for Enterprise](https://codenotary.com/hubfs/AgentMon%20for%20Enterprise.svg) **AgentMon** Currently monitors more \> 7 million agent interactions/day. TRY NOW →](https://codenotary.com/agentmon)
  
  #### [![AgentX](https://codenotary.com/hubfs/AgentX.svg) **AgentX** Agentic network control middleware. TRY NOW →](https://codenotary.com/agent-network-control)
  
  #### [![Autonomous Security](https://codenotary.com/hubfs/Autonomous%20Security.svg) **Autonomous Security** AI Agents keep your servers secure. TRY NOW →](https://codenotary.com/trust)
- Use Cases
  
  #### [**AI Agent Risk Monitoring** Continuous oversight of autonomous agents across every environment.](https://codenotary.com/use-cases#risk)
  
  #### [**Autonomous Security Operations** Self-healing defenses that detect, contain, and remediate threats.](https://codenotary.com/use-cases#agentops)
  
  #### [**AI Coding Governance & Performance Monitoring** AI-generated code reviewed, tracked, and held to quality standards.](https://codenotary.com/use-cases#performance)
  
  #### [**AI Tool Cost & Usage Optimization** Spend and consumption optimized across every AI service in use.](https://codenotary.com/use-cases#cost)
  
  #### [**AI Tool Security & Policy Enforcement** Approved AI usage enforced with guardrails and policy controls.](https://codenotary.com/use-cases#security#security)
  
  #### [**Shadow AI Governance** Unsanctioned AI tools discovered, surfaced, and brought under control.](https://codenotary.com/use-cases#shadowit)
- [Blog](https://codenotary.com/blog)
- [Press](https://codenotary.com/press)
- Resources
  
  #### [**Integrations** Connect with your favorite tools and platforms. LEARN MORE →](https://codenotary.com/integrations)
  
  #### [**Support** Get help from our dedicated support team. GET HELP →](https://support.codenotary.com)
  
  #### [**Success Stories** Read how customers achieve their goals. READ MORE →](https://codenotary.com/success)
  
  #### [**Learn** Access documentation and learning resources. EXPLORE →](https://codenotary.com/learn)

[Login](https://apps.codenotary.com/auth/login)

[All posts](https://codenotary.com/blog/all)

 Jun 26, 2024

# GitHub's Latest Dependency Graph Update: What Developers Need to Know

 By  [blog](https://codenotary.com/blog/author/blog)  ·   2 minute read

On June 11th, GitHub rolled out an important update to its dependency graph feature that promises to improve how to manage software dependencies. This update is a crucial step towards more accurate and comprehensive Software Bill of Materials (SBOM) generation, especially when dealing with version ranges in manifest files.

![CN-Assets (77)](https://codenotary.com/hs-fs/hubfs/CN-Assets%20(77).png?width=1200&height=630&name=CN-Assets%20(77).png)

### The Challenge with Version Ranges

Previously, when a manifest file included a version range of a package (e.g., `version < 3`), GitHub faced limitations in generating a complete SBOM. The SBOM, a key document for understanding the components and dependencies of a software project, would often lack a crucial element: the package URL (purl). Without the purl, identifying the specific packages in use became challenging, potentially leading to gaps in security and dependency management.

### What Has Changed?

With the latest update, GitHub has improved the SBOM generation process. Now, when a manifest file references a package within a range, the generated SBOM will include the purl even if the version field is not specified. This change adheres to the SBOM specification, where the version field is optional, thus allowing for more flexibility and completeness in the data provided.

### Benefits for Developers and DevOps Engineers

1. **Enhanced Clarity:** Including the purl in the SBOM, despite the absence of a specific version, provides a clearer identification of the packages being used in a repository. This makes it easier to track and manage dependencies accurately.
2. **Improved Security:** More comprehensive SBOMs mean better visibility into the software supply chain. This visibility is crucial for identifying and mitigating security vulnerabilities, ensuring all components are accounted for and up-to-date.
3. **Better Compliance:** Adhering to industry standards and regulatory requirements is simplified with more complete SBOMs. This update helps organizations remain compliant with supply chain security mandates by providing detailed and accurate dependency information.

### How to Leverage the Updated Dependency Graph

To make the most of this update, developers and DevOps engineers should:

- **Review and Update Manifest Files:** Ensure that manifest files in your repositories are up-to-date and correctly reference all dependencies. While the purl will be included even for ranges, having accurate version information where possible remains a best practice.
- **Regularly Monitor SBOMs:** Incorporate regular checks of the generated SBOMs into your workflow. This will help you stay on top of any changes in dependencies and address potential issues proactively.
- **Utilize GitHub's Security Features:** Take advantage of GitHub's suite of security tools, such as Dependabot alerts and automated security updates, which work hand-in-hand with the enhanced SBOM data to keep your projects secure.

### Conclusion

The June 11th update to GitHub's dependency graph is a significant enhancement for the developer and DevOps communities. By including the purl in SBOMs for packages referenced by version ranges, GitHub has made it easier to manage and secure software dependencies. This update not only improves the accuracy of dependency tracking but also strengthens the overall security posture of software projects.

For more details on how to use and benefit from the GitHub dependency graph, visit the [GitHub documentation](https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-the-dependency-graph).

![CN-Assets (78)](https://codenotary.com/hs-fs/hubfs/CN-Assets%20(78).png?width=1200&height=630&name=CN-Assets%20(78).png)

Embrace this update to enhance your software supply chain management and security practices today.

[![Share on twitter](https://4059529.fs1.hubspotusercontent-na1.net/hub/4059529/hubfs/01-marketplace/twitter-color.png?width=35&height=35&name=twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://codenotary.com/blog/enhanced-github-dependency-graph-for-sboms&utm_medium=social&utm_source=twitter&url=https://codenotary.com/blog/enhanced-github-dependency-graph-for-sboms&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on facebook](https://4059529.fs1.hubspotusercontent-na1.net/hub/4059529/hubfs/01-marketplace/facebook-color.png?width=35&height=35&name=facebook-color.png)](http://www.facebook.com/share.php?u=https://codenotary.com/blog/enhanced-github-dependency-graph-for-sboms&utm_medium=social&utm_source=facebook) [![Share on linkedin](https://4059529.fs1.hubspotusercontent-na1.net/hub/4059529/hubfs/01-marketplace/linkedin-color.png?width=35&height=35&name=linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://codenotary.com/blog/enhanced-github-dependency-graph-for-sboms&utm_medium=social&utm_source=linkedin) [![Share on pinterest](https://4059529.fs1.hubspotusercontent-na1.net/hub/4059529/hubfs/pinterest.jpg?width=35&height=35&name=pinterest.jpg)](http://pinterest.com/pin/create/button/?url=https://codenotary.com/blog/enhanced-github-dependency-graph-for-sboms&utm_medium=social&utm_source=pinterest&media=)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "blog",
    "url" : "https://codenotary.com/blog/author/blog"
  },
  "dateModified" : "2024-06-26T15:28:38.529Z",
  "datePublished" : "2024-06-26T15:28:38.000Z",
  "headline" : "GitHub's Latest Dependency Graph Update: What Developers Need to Know",
  "image" : [ "https://codenotary.com/hubfs/CN-Assets%20(77).png" ],
  "mainEntityOfPage" : {
    "@id" : "https://codenotary.com/blog/enhanced-github-dependency-graph-for-sboms",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://codenotary.com/hubfs/logo-light.svg"
    },
    "name" : "Codenotary, Inc."
  }
}
```

```json
{
  "@context" : "http://schema.org",
  "@type" : "Article",
  "author" : {
    "@type" : "Person",
    "name" : [ "blog" ],
    "url" : "https://codenotary.com/blog/author/blog"
  },
  "datePublished" : "2024-06-26T15:28:38+0000",
  "description" : "latest update to GitHub's dependency graph, enhancing SBOM generation with precise package URLs",
  "headline" : "GitHub's Latest Dependency Graph Update: What Developers Need to Know",
  "image" : "https://23873599.fs1.hubspotusercontent-na1.net/hubfs/23873599/CN-Assets%20%2877%29.png",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://cdn2.hubspot.net/hubfs/23873599/logo-light.svg"
    },
    "name" : ""
  },
  "url" : "https://codenotary.com/blog/enhanced-github-dependency-graph-for-sboms"
}
```