GitHub Dependabot
Automatically scan dependencies for vulnerabilities and create pull requests to keep them updated
- Also known as
- github-dependabot
Available worldwide
What is GitHub Dependabot?
An automated tool integrated into GitHub workflows that detects vulnerable dependencies, generates update pull requests, and enforces security and compliance policies to protect software supply chains.
GitHub Dependabot pricing
Plans, per-tier features and add-ons, dated and linked to live pricing. Pricing changes often; always verify at source before you rely on it.
Free for public repositories; included in paid GitHub plans
Free
FreeDependabot for public repositories
- ci_cd_minutes
- 2000/month
- Dependabot vulnerability detection
- Automated dependency pull requests
- Public repository access
Enterprise Cloud
Contact salesMulti-tenant SaaS with regional deployment options
- ci_cd_minutes
- 50000/month
- Dependabot with automated triage rules
- Dependency review enforcement
- Advanced Security integration
- Audit log API
What GitHub Dependabot does
The capabilities that matter for dependency management, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.
- Update automation
- ✓
- Vuln scanning
- ✓
- Reachability analysis
- -
- License compliance
- ✓
- Sbom generation
- ✓
- Ci gating
- ✓
- Container image scanning
- -
- Auto merge policy
- ✓
- Open source
- ✓
Platform & deployment
Independently observed- CLI
- Web
- Cloud / SaaS
- On-premise
- Self-hosted
Integrations (15)
Independently observed- Azure Pipelines
- Linear
- Zenhub
- Codacy
- CodeFactor
- Rollbar
- Percy
- WakaTime
- Codemagic
- Zube
- Codetree
- POEditor
- Imgbot
- Qlty Cloud
- Render
GitHub Dependabot alternatives
Other dependency management we track, ranked by the same independent score.
- OWASP Dependency-Tracklow · 28%
- OWASP Dependency-Checklow · 10%
- FOSSAAutomated open source dependency, license, and vulnerability management platform for controlling software supply chainsmedium · 56%
- pip-auditlow · 26%
- TideliftStatic code analysis platform for identifying security vulnerabilities, quality issues, and technical debt in software developmentlow · 29%
- Sonatype LifecycleAutomatically manage open source dependencies and identify vulnerabilities across your software supply chainlow · 15%
Compare GitHub Dependabot
Side by side against other dependency management, attribute by attribute, with a source on every value.
The Vioscale score: one lens on the evidence
Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for GitHub Dependabot, not the verdict.
| Signal | Score | Weight | Contribution | Evidence |
|---|---|---|---|---|
| Pricing transparency | 80 | 0.08 | 6.7 | ✓ |
| Price level | 100 | 0.05 | 5.2 | ✓ |
| Capabilities | 87 | 0.05 | 4.2 | ✓ |
| Reliability | 50 | 0.07 | 3.7 | ✓ |
| Security posture | 45 | 0.07 | 3.3 | ✓ |
| Integrations | 35 | 0.04 | 1.4 | ✓ |
Computed . Re-weight it by intent, or see the full method.
All data & sourcesshow ↓
Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.
Features
| Attribute | Value | Evidence |
|---|---|---|
| Capabilities | Ci gating, Open source, Vuln scanning, Sbom generation, Auto merge policy, Update automation, License compliance | mediumsource · 2026-08-25 · 60% |
Integrations
| Attribute | Value | Evidence |
|---|---|---|
| Count | 15 | mediumsource · 2026-08-25 · 60% |
Market
| Attribute | Value | Evidence |
|---|---|---|
| Availability | PrimaryMarkets: … · AvailabilityScope: global · AvailableCountries: … · NotAvailableCountries: … | highsource · 2026-08-25 · 75% |
Pricing
Reliability
| Attribute | Value | Evidence |
|---|---|---|
| Status page | Yes | mediumsource · 2026-08-25 · 60% |