

Dependabot
Keep your dependencies on GitHub up to date without the automatic creation of the Pull Requests to update the dependency and checking for the known vulnerabilities.
https://github.blog/2020-06-01-keep-all-your-packages-up-to-date-with-dependabot/
Cost / License
- Free
- Open Source (MIT)
Application type
Platforms
- Online
- Software as a Service (SaaS)
- GitHub
- GitLab
Features
- Picture in Picture
Git Support
Support for Docker
- Nuget
- Dependency Tracking
- Dependencies
- Swift App
- Supports Python
- NPM
Dependabot News & Activities
Recent activities
glatisant added Dependabot as alternative to Exploit Observer
Sonu-Kapoor added Dependabot as alternative to CVE Lite CLI- solvionsolutions added Dependabot as alternative to Guardlayer
auditdude added Dependabot as alternative to AuditDude
DanielWestgaard added Dependabot as alternative to Riftmap
alexguidioff added Dependabot as alternative to Patchdex
Proscan added Dependabot as alternative to Proscan AppSec
metriclogic added Dependabot as alternative to PackageFix
elevenapril added Dependabot as alternative to SkillRisk
dcentrica added Dependabot as alternative to Metaport
Dependabot information
What is Dependabot?
Keeping your dependencies updated is one of the easiest ways to keep the software you build secure. However, while it’s critically important to keep your dependencies updated, in a recent survey, 52% of developers said they find it painful1. Dependabot alleviates that pain by updating your dependencies automatically, so you can spend less time updating dependencies and more time building. Up until now, the Dependabot features we’ve brought to GitHub have focused on automated security updates, which update packages that have known vulnerabilities.


Comments and Reviews
It's very simple to use, open-source, self-hostable, supports a lot of package types, uses YAML config file for easy manipulation, what more could you ask?