

Dependabot
Keep your dependencies on GitHub up to date without the automatic creation of the Pull Requests to update the dependency and checking for the known vulnerabilities.
https://github.blog/2020-06-01-keep-all-your-packages-up-to-date-with-dependabot/
Cost / License
- Free
- Open Source
Application type
Platforms
- Online
- Software as a Service (SaaS)
- GitHub
- GitLab
Features
- Picture in Picture
Git Support
Support for Docker
- Nuget
- Dependency Tracking
- Dependencies
- Swift
- Supports Python
- NPM
Tags
- Python
- dependency-management
- Python Development
- bundler
- maven
- gradle
- cargo
- docker-registry
- Web service
- terraform
- GitHub
- Software as a Service
- composer
- development
- GitHub Actions
- Security Utilities
- Software Composition Analysis
- gitlab
- poetry
Dependabot News & Activities
Recent activities
dcentrica added Dependabot as alternative to Metaport
block_hacks added Dependabot as alternative to NPMScan- jdwalker updated Dependabot
Dependabot information
What is Dependabot?
Keeping your dependencies updated is one of the easiest ways to keep the software you build secure. However, while it’s critically important to keep your dependencies updated, in a recent survey, 52% of developers said they find it painful1. Dependabot alleviates that pain by updating your dependencies automatically, so you can spend less time updating dependencies and more time building. Up until now, the Dependabot features we’ve brought to GitHub have focused on automated security updates, which update packages that have known vulnerabilities.



Comments and Reviews
It's very simple to use, open-source, self-hostable, supports a lot of package types, uses YAML config file for easy manipulation, what more could you ask?