Skip to main content
    My stack

    Dependabot

    GitHub's free, built-in bot that opens pull requests to patch vulnerable or outdated dependencies.

    Visit website
    ToolTrim verdict4.2/ 5Great

    No cost threshold applies; enable it regardless of team size or budget.

    Dependabot, preview 1
    About

    In practice. What you can do with Dependabot.

    Dependabot is a built-in GitHub feature, not a separate product to buy: it scans a repository's dependency graph and opens pull requests to patch known vulnerabilities or bump outdated packages. It is free on every GitHub plan, public or private repo, with no usage cap.

    It is deliberately narrow: it patches dependencies and GitHub Actions versions, and groups fixes to cut down on pull request noise, but it does not scan source code or secrets. Those live in GitHub's paid Advanced Security add-ons, billed separately per active committer.

    For most transitive-dependency ecosystems (npm excluded), Dependabot cannot patch an indirect dependency if its parent also needs updating, so some fixes still land on a human.

    Practical uses

    • Automatically receiving a pull request when a dependency in a repo has a known security vulnerability.
    • Keeping GitHub Actions workflow versions patched against known CVEs without manual tracking.

    Features & use cases

    Security

    Pros and cons. What Dependabot does well, and what to expect.

    Pros

    • Completely free on every plan, no seat or usage cost.
    • Works out of the box on any GitHub repo with minimal configuration.
    • Grouped updates reduce pull request noise for large dependency trees.

    Cons

    • Cannot patch transitive dependencies in most ecosystems when the parent also needs updating.
    • Only covers dependencies and Actions; code and secret scanning require separate paid GitHub Advanced Security add-ons.

    When it makes sense. Keep Dependabot, or challenge it?

    Keep if

    • Your code lives on GitHub; there is no reason not to enable it, since it is free.

    Challenge if

    • You need code or secret scanning, which Dependabot does not do on its own.

    Pricing. What does Dependabot cost ?

    Free

    $0

    Permanent free plan

    • No limits: included free on every GitHub plan for public and private repositories

    Official pricingChecked on September 25, 2026

    Dependabot's billing traps

    Before you pay

    None: Dependabot itself carries no charge. Only the separate GitHub Advanced Security add-ons bill per active committer.

    Our verdict. What to know about Dependabot.

    Why this verdict

    Great

    Added value

    Free on every GitHub plan for public and private repos, removing a real security risk at zero cost.

    Simplicity

    Enabling Dependabot alerts and updates takes a couple of settings toggles or a minimal dependabot.yml file.

    Fit for purpose

    Opens working pull requests for patchable vulnerabilities as advertised, though transitive-dependency limits mean some fixes still need manual work.

    Performance

    Covers dependency and Actions patching well, but stays narrower than a full application security platform (no secret scanning, no code scanning included).

    Reversibility

    Dependabot only opens standard pull requests in the repo; disabling it leaves no lock-in and no data to migrate.

    Dependabot Summary

    Category
    productivity tool.
    Price from
    Free.
    Best for
    Fits any developer or small team hosting code on GitHub who wants dependency vulnerabilities patched automatically.
    Avoid if
    You need code or secret scanning, which Dependabot does not do on its own.
    ToolTrim verdict
    No cost threshold applies; enable it regardless of team size or budget.

    Frequently asked questions.

    What to know before choosing Dependabot.

    What is Dependabot used for?

    GitHub's free, built-in bot that opens pull requests to patch vulnerable or outdated dependencies.

    How much does Dependabot cost?

    Dependabot costs $0 (free). Price verified on 2026-09-25.

    Is Dependabot suitable for beginners?

    Fits any developer or small team hosting code on GitHub who wants dependency vulnerabilities patched automatically.

    Is Dependabot worth the price?

    No cost threshold applies; enable it regardless of team size or budget.

    What are the best alternatives to Dependabot?

    The main alternatives to Dependabot are: Snyk, GitHub Advanced Security. Free alternatives: Snyk, GitHub Advanced Security.

    DependabotFree
    Visit