GitHub Dependabot

Automatically scan dependencies for vulnerabilities and create pull requests to keep them updated

Also known as
github-dependabot

Available worldwide

What is GitHub Dependabot?

An automated tool integrated into GitHub workflows that detects vulnerable dependencies, generates update pull requests, and enforces security and compliance policies to protect software supply chains.

Independently observed

GitHub Dependabot pricing

Plans, per-tier features and add-ons, dated and linked to live pricing. Pricing changes often; always verify at source before you rely on it.

Pricing as of verify at live pricing ↗Independently observed
FreeFree tier30-day trial

Free for public repositories; included in paid GitHub plans

Free

Free
Free

Dependabot for public repositories

ci_cd_minutes
2000/month
  • Dependabot vulnerability detection
  • Automated dependency pull requests
  • Public repository access

Enterprise Cloud

Contact sales
Contact sales

Multi-tenant SaaS with regional deployment options

ci_cd_minutes
50000/month
  • Dependabot with automated triage rules
  • Dependency review enforcement
  • Advanced Security integration
  • Audit log API

What GitHub Dependabot does

The capabilities that matter for dependency management, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.

Capabilities
Update automation
Vuln scanning
Reachability analysis
-
License compliance
Sbom generation
Ci gating
Container image scanning
-
Auto merge policy
Open source
Independently observed

Platform & deployment

Independently observed
Platforms
  • CLI
  • Web
Deployment
  • Cloud / SaaS
  • On-premise
  • Self-hosted

Integrations (15)

Independently observed
  • Azure Pipelines
  • Linear
  • Zenhub
  • Codacy
  • CodeFactor
  • Rollbar
  • Percy
  • WakaTime
  • Codemagic
  • Zube
  • Codetree
  • POEditor
  • Imgbot
  • Qlty Cloud
  • Render

GitHub Dependabot alternatives

Other dependency management we track, ranked by the same independent score.

All GitHub Dependabot alternatives, ranked →

Compare GitHub Dependabot

Side by side against other dependency management, attribute by attribute, with a source on every value.

Independent · unbought · dated

The Vioscale score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for GitHub Dependabot, not the verdict.

Balanced composite 66 / 100
high · 76%updating
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Pricing transparency800.086.7
Price level1000.055.2
Capabilities870.054.2
Reliability500.073.7
Security posture450.073.3
Integrations350.041.4

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Features

AttributeValueEvidence
CapabilitiesCi gating, Open source, Vuln scanning, Sbom generation, Auto merge policy, Update automation, License compliancemediumsource · 2026-08-25 · 60%

Integrations

AttributeValueEvidence
Count15mediumsource · 2026-08-25 · 60%

Market

AttributeValueEvidence
AvailabilityPrimaryMarkets: … · AvailabilityScope: global · AvailableCountries: … · NotAvailableCountries: …highsource · 2026-08-25 · 75%

Pricing

AttributeValueEvidence
Free tierYesmediumsource · 2026-08-25 · 60%
Modelfreemediumsource · 2026-08-25 · 60%
Price levelfreemediumsource · 2026-08-25 · 60%
TransparentYesmediumsource · 2026-08-25 · 60%

Reliability

AttributeValueEvidence
Status pageYesmediumsource · 2026-08-25 · 60%

Security

AttributeValueEvidence
Soc2Yeshighsource · 2026-08-25 · 75%
FedrampYeshighsource · 2026-08-25 · 75%
GdprYeshighsource · 2026-08-25 · 75%