Skip to main content
    My stack

    Dependabot reviews

    GitHub's free, built-in bot that opens pull requests to patch vulnerable or outdated dependencies.

    Visit website
    ToolTrim verdict4.2/ 5Great

    No cost threshold applies; enable it regardless of team size or budget.

    Dependabot, preview 1
    About

    In practice. What you can do with Dependabot.

    Dependabot is a built-in GitHub feature, not a separate product to buy: it scans a repository's dependency graph and opens pull requests to patch known vulnerabilities or bump outdated packages. It is free on every GitHub plan, public or private repo, with no usage cap.

    It is deliberately narrow: it patches dependencies and GitHub Actions versions, and groups fixes to cut down on pull request noise, but it does not scan source code or secrets. Those live in GitHub's paid Advanced Security add-ons, billed separately per active committer.

    For most transitive-dependency ecosystems (npm excluded), Dependabot cannot patch an indirect dependency if its parent also needs updating, so some fixes still land on a human.

    Practical uses

    • Automatically receiving a pull request when a dependency in a repo has a known security vulnerability.
    • Keeping GitHub Actions workflow versions patched against known CVEs without manual tracking.

    Features & use cases

    Security

    Pros and cons. What Dependabot does well, and what to expect.

    Pros

    • Completely free on every plan, no seat or usage cost.
    • Works out of the box on any GitHub repo with minimal configuration.
    • Grouped updates reduce pull request noise for large dependency trees.

    Cons

    • Cannot patch transitive dependencies in most ecosystems when the parent also needs updating.
    • Only covers dependencies and Actions; code and secret scanning require separate paid GitHub Advanced Security add-ons.

    When it makes sense. Keep Dependabot, or challenge it?

    Keep if

    • Your code lives on GitHub; there is no reason not to enable it, since it is free.

    Challenge if

    • You need code or secret scanning, which Dependabot does not do on its own.

    Our verdict. What to know about Dependabot.

    Why this verdict

    Great

    Added value

    Free on every GitHub plan for public and private repos, removing a real security risk at zero cost.

    Simplicity

    Enabling Dependabot alerts and updates takes a couple of settings toggles or a minimal dependabot.yml file.

    Fit for purpose

    Opens working pull requests for patchable vulnerabilities as advertised, though transitive-dependency limits mean some fixes still need manual work.

    Performance

    Covers dependency and Actions patching well, but stays narrower than a full application security platform (no secret scanning, no code scanning included).

    Reversibility

    Dependabot only opens standard pull requests in the repo; disabling it leaves no lock-in and no data to migrate.

    DependabotFree
    Visit