Automated dependency updates

Dependabot creates pull requests to keep your dependencies secure and up-to-date.

Sign up Learn how it works

Over 75,000 pull requests merged, and counting!

How it works

1

Dependabot checks for updates

Dependabot pulls down your dependency files and looks for any outdated or insecure requirements.

2

Dependabot opens pull requests

If any of your dependencies are out-of-date, Dependabot opens individual pull requests to bump each one.

3

You review and merge

You check your tests pass, scan the included changelog and release notes, then hit merge with confidence.

Screenshot of a Dependabot pull request

Features

Simple, drip-feed getting started flow

We'll update five of your dependencies each day, until you're on the cutting edge. Request more PRs if you want, or close them to ignore a dependency until the next release.

Live, daily, weekly or monthly updates

Choose to receive update PRs live, daily, weekly or monthly. We make an exception for security patches, which you'll always receive immediately.

Great pull requests that stay up-to-date

Dependabot PRs include release notes, changelogs, commit links and vulnerability details whenever they're available. They'll also automatically keep themselves conflict-free.

Compatibility scores for each update

Dependabot aggregates everyone's test results into a compatibility score, so you can be certain a dependency update is backwards compatible and bug-free.

Automatic merge options

Dependabot can be configured to automatically merge PRs if your tests pass on them, based on the size of the change (security/patch/minor/major) and the dependency type.

Security advisories handled automatically

Dependabot monitors security advisories for Ruby, JavaScript, PHP, Elixir and Rust. We create PRs immediately in response to new advisories.

Trusted by

... plus 1,200 more, who have merged over 75,000 Dependabot pull requests.

Pricing

Open Source / Personal Account

Public repos and personal account repos are free

$0 per month

Small Organization

Up to 5 private projects on an organization account

$15 per month

Free trial for 14 days!

Unlimited

Unlimited private projects on an organization account

$50 per month

Free trial for 14 days!

Our GitHub Enterprise solution will launch at the beginning of June - please contact us.

Get started

Dependabot is a GitHub integration, so you can try it on a single repository.
Set up takes less than a minute.

Sign up