Free dependency updates and vulnerability alerts, built into GitHub.
Dependabot monitors your manifests for outdated and vulnerable dependencies and opens pull requests to update them, with grouped updates and configurable schedules. It is free on every GitHub repository, public or private, which makes it the default baseline for dependency hygiene.
Best for
Free
FreeFree tier: Free on all GitHub repositories including private ones.
What drives the bill: Completely free. Advanced Security features such as code scanning are separately licensed.
Check current pricing on GitHub (Microsoft)’s siteFigures are indicative and were last reviewed August 2026. Vendors change pricing often; confirm before you commit.
No reviews of Dependabot yet. If you have used it in anger, yours would be the first.
If Dependabot is not the right fit, these solve the same problem differently.
Security Testing
Developer-first security across dependencies, code, containers and infrastructure.
Security Testing
Highly configurable automated dependency updates, free and self-hostable.
Security Testing
Software composition analysis with automated remediation and licence compliance.