Dependabot
-
Categories
Dependency management -
Supported languages
Dockerfile, Java, JavaScript and -
Developer links
Dependabot helps you keep your Ruby, JavaScript, Python, PHP and Java dependencies up to date. Every day, it checks your dependency files for outdated requirements and opens individual pull requests for any it finds. You review the PRs, merge them, and get to work on the latest, most secure releases.
More about Dependabot
Great pull requests that stay up-to-date
Dependabot PRs include release notes, changelogs and commit links whenever they're available. They'll also automatically keep themselves conflict-free.
Compatibility scores for each update
Dependabot aggregates everyone's test results into a compatibility score, so you can be certain a dependency update is backwards compatible and bug-free.
Simple, drip-feed getting started flow
We'll update five of your dependencies each day, until you're on the cutting edge. Request more PRs if you want, or close them to ignore a dependency until the next release.
Daily, weekly, or monthly update options
Choose to receive update PRs daily, weekly or monthly. Think of it like brushing your teeth regularly rather than occasionally making painful trips to the dentist.
Pricing and setup
Small organisation
Daily dependency update for up to five private repos
- Unlimited public repos
- 5 private repos
Dependabot is provided by a third-party and is governed by separate terms, privacy policy, and support contact.