Help developers discover the tools you use. Get visibility for your team's tech choices and contribute to the community's knowledge.
Stop vulnerabilities, automate compliance, and mitigate third-party risk in your applications | Dependabot helps you keep your dependencies up to date. Every day, it checks your dependency files for outdated requirements and opens individual PRs for any it finds. You review, merge, and get to work on the latest, most secure releases. |
| - | Simple, drip-feed getting started flow; Security advisories handled automatically; Great pull requests that stay up-to-date; Compatibility scores for each update; Powerful configuration options; Live, daily, weekly or monthly updates |
Statistics | |
GitHub Stars 1.4K | GitHub Stars - |
GitHub Forks 185 | GitHub Forks - |
Stacks 28 | Stacks 102 |
Followers 37 | Followers 113 |
Votes 4 | Votes 1 |
Pros & Cons | |
Pros
| Pros
|
Integrations | |

Automatically find & fix vulnerabilities in your code, containers, Kubernetes, and Terraform

Automatically review updates for breaking changes & code impact. Works alongside Dependabot, Renovate & Snyk for JavaScript / TypeScript.

It is an addictive Inversion of Control container for .NET Core, ASP.NET Core, .NET 4.5.1+, Universal Windows apps, and more. It provides activation events to let you know when components are being activated or released, allowing for a lot of customization with little code.

Real-time monitoring for npm dependencies. Let a bot send you informative and actionable issues so you can easily keep your software up to date and in working condition.

The leading solution for agile open source security and license compliance management, WhiteSource integrates with the DevOps pipeline to detect vulnerable open source libraries in real-time.

It is a developer-first software security app. It scans your source code & cloud to show you which vulnerabilities are actually important to solve. We speed up triaging by massively reducing false positives and making CVEs human-readable.

Automatic compliance testing for all of the dependencies in your application.

Gemnasium keeps track of projects dependencies. Ruby, Node.js, PHP composer, Bower and Python projects dependencies are automatically parsed, and notifications sent when new versions are released or security advisories are published.

Doppins creates informative pull requests and commit messages in a timely fashion, and includes a changelog for the released version if available.

Makes open-source security tools easily available in your Pull Requests. Continuously identifies security problems in your codebase and helps you fix them.