Supply Chain Siege

Dependabot alerts march at your release train. Route every one before it lands. Under-react and a vulnerability breaches production. Over-react and you snap the build. Your routing decisions write a real dependabot.yml — you get to read it at the end.

Up to five lanes
Auto-merge · Grouped PR · Dismiss · Ignore rule · Block at the dependency review gate. The lower tiers open fewer of them — dismiss-versus-ignore is a tier-300 idea, so it is not on the board before then.
Damage is visible
Breach −25 HP. Build break −12 HP. A card that reaches the train un-routed −25 HP and a lecture.
Boss waves
Transitive vulnerabilities behind a locked-down private registry. Routing alone will not save you — you have to configure.
Controls

A auto-merge · G group · D dismiss · I ignore · B block. Or number the lanes you can actually see — 1 is the leftmost open lane, and the lower tiers open fewer of them. Sub-questions use 15. Tap on touch.

Correct route +100 × combo · sub-question +60 · distance left × 60 · every wave survived +250. Everything is then multiplied by the tier: ×0.6 at 100 up to ×1.6 at 500.

The tier changes the deck and the siege: how many lanes are open, how much health the train has, how fast the cards march, how many options a configuration question offers, and what a point is worth. Best scores are kept per tier.

GH-500 track ← Hub

What this drills

Whiteboards: Dependabot & Supply Chain · Enablement, Policy & Rollout · Secret Scanning · The Pizza Parlor

← Back to the hub