Dependabot
Dependabot is an automated dependency management tool, acquired by GitHub in 2019 and integrated into GitHub Advanced Security, that monitors code repositories for outdated or vulnerable packages and creates pull requests to update them. It serves enterprise and SMB software development teams via GitHub Enterprise Cloud and Server at $30 per active committer per month.
- Company typePrivate
- Founded2017
- HeadquartersLondon, United Kingdom
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Dependabot does
Dependabot is an automated dependency management tool that monitors software repositories for outdated or vulnerable third-party packages and creates pull requests to update them to safer versions. The product was co-founded in 2017 by Grey Baker and acquired by GitHub in 2019, after which it was integrated directly into the GitHub platform as a component of GitHub Advanced Security. Technically, Dependabot scans project dependency manifests, identifies new releases or known vulnerabilities, and generates pull requests — including support for auto-merge workflows — so that updates can propagate across many repositories quickly. The product has added features such as OpenID Connect (OIDC) authentication (2026-02) for secure access to private package registries using short-lived, dynamically generated credentials, and combines with CodeQL-based code scanning and secret protection under the broader GitHub Code Security umbrella.
Dependabot operates as a feature inside GitHub rather than a standalone commercial product. Revenue accrues through GitHub Advanced Security, where GitHub Code Security (which bundles Dependabot's vulnerability detection) is priced at $30 per active committer per month on a subscription basis, available to GitHub Enterprise Cloud and GitHub Enterprise Server customers. The go-to-market is product-led and self-serve: Dependabot is activated within the GitHub UI without a separate procurement motion, and adoption scales with GitHub's installed base of enterprise developers. The named customer base disclosed on the GitHub Advanced Security page includes FedEx, American Airlines, Postmates, Mercado Libre, KPMG, LinkedIn, Otto Group, Telus, 3M, Carlsberg Group, and Deutsche Vermögensberatung, reflecting horizontal reach across software development teams in multiple industries.
The company has no independent headcount disclosure following the 2019 acquisition; co-founder Grey Baker has since departed, co-founded Pincites (acquired by Filevine), and joined Y Combinator as a General Partner. Dependabot has no patents, trademarks, awards, or independent regulatory disclosures in the source data, and its standalone KPIs are not publicly reported — its strategic and financial trajectory is functionally a subset of GitHub Advanced Security within Microsoft.
Dependabot firmographics
Firmographics- Name
- Dependabot
- Legal name
- Dependabot
- Website
- https://dependabot.com
- Company type
- Private
- Founded year
- 2017
- Operating status
- Acquired
- Headcount range
- 11–50 employees
- Short description
- Dependabot is an automated dependency management tool, acquired by GitHub in 2019 and integrated into GitHub Advanced Security, that monitors code repositories for outdated or vulnerable packages and creates pull requests to update them. It serves enterprise and SMB software development teams via GitHub Enterprise Cloud and Server at $30 per active committer per month.
- Ownership category
- akta.pro rank
Dependabot industry classification
Industry- Product category
- Application Security
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Code & Repository Security (Git Security, Code Integrity) (HDADACAG)
- akta.pro secondary industries
- Application Security & DevSecOps Services (BPAKAHAJ), Application Security & Secure Software (DevSecOps) (EDAOAIAK)
Keywords
Where Dependabot is headquartered
LocationHeadquarters
- HQ city
- London
- HQ country
- United Kingdom
- HQ region
- Europe
Offices1 record
Markets served
Dependabot business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Infrastructure, Operations
Revenue model
- GitHub Advanced Security Subscription: Dependabot is included as part of GitHub Advanced Security offerings, which are subscription-based per active committer. GitHub Code Security (which includes Dependabot's vulnerability detection capabilities) is priced at $30 per active committer/month.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Per seat | Monthly | GitHub Code Security (includes Dependabot) - $30 per active committer/month |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels1 record
Dependabot product offering
Product offeringCore offering
Dependabot is an automated dependency update tool that monitors software repositories for outdated or vulnerable dependencies and automatically creates pull requests to update them to secure versions. It scans dependencies for known security vulnerabilities and generates alerts and fix pull requests, integrating directly into GitHub's native development workflows as part of GitHub Advanced Security.
Product overview
Dependabot is a single, focused product offering automated dependency management. It monitors code repositories for outdated or vulnerable dependencies and automatically creates pull requests to update them. The product was co-founded by Grey Baker (acquired by GitHub in 2019) and operates as an integrated feature within the GitHub platform.
Differentiator
Problem solved
Functional benefit
Products and services
- Dependabot Automated dependency update tool that monitors software repositories for outdated or vulnerable dependencies and automatically creates pull requests to update them to secure versions. Distributed as an integrated feature within the GitHub platform for software development teams and enterprises.
Quantifiable outcome
- Automated dependency updates can propagate to hundreds of repositories in under an hour through auto-merge workflows
- +1 more outcomes
Companies that use Dependabot
Customer profileNamed customers1 record
Segments1 record
Ideal customer profiles2 records
Dependabot technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Dependabot partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- GitHubcoreDependabot was co-founded by Grey Baker and acquired by GitHub in 2019. Following the acquisition, Dependabot became an integral part of GitHub's security product suite, integrated into GitHub Advanced Security offerings for automated dependency updates and vulnerability detection.
Scale indicators1 record
Recent moves4 records
Expansion highlights3 records
Dependabot competitors and assessment
Company assessmentDirect peers
- Renovate: Open-source automated dependency update tool that creates pull requests to keep project dependencies current. It is the closest direct competitor to Dependabot in functionality and developer workflow.
- Snyk: Developer security platform offering dependency vulnerability scanning, fix advice, and automated PRs via Snyk Open Source. Competes head-on with Dependabot for supply chain and dependency security budgets.
- Mend (formerly WhiteSource): Software composition analysis and dependency security vendor targeting enterprise customers. Overlaps with Dependabot on SBOM generation, vulnerability detection, and automated remediation.
- Sonatype Nexus: Provider of Nexus Repository and Nexus Lifecycle for software supply chain management. Directly comparable to Dependabot on dependency monitoring, policy enforcement, and vulnerability alerts.
Broad incumbents
- GitLab Dependency Scanning: Integrated CI/CD and DevSecOps platform offering dependency and container scanning as part of its broader DevOps suite. Competes with Dependabot through an alternative end-to-end platform rather than a focused dependency tool.
- JFrog Xray: Application security component of the JFrog platform that performs deep dependency and artifact scanning. Comparable in supply chain security scope though bundled into JFrog's broader artifact management platform.
- GitHub: Parent platform and host of Dependabot since 2019. Comparable as the broader security suite (GitHub Advanced Security, CodeQL, Secret Protection) within which Dependabot's capabilities are bundled and sold.
Emerging players
- Socket: Developer-focused supply chain security startup that detects malicious and risky open-source dependencies. Partial overlap with Dependabot on dependency risk detection, with a stronger focus on proactive malware and behavioral analysis.
- Endor Labs: Startup applying reachability analysis and usage-based prioritization to dependency security. Competes in the same application security and dependency management category as Dependabot with a differentiated prioritization model.
- Chainguard: Supply chain security vendor focused on hardened base images and signed, provenance-attested dependencies. Adjacent to Dependabot's supply chain mission, with emphasis on artifact integrity rather than update automation.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
Dependabot social profiles
Digital presenceDependabot financial estimates
Financial estimateRevenue estimate
Valuation estimate
Dependabot leadership team
Management profileNumber of profiles
Dependabot funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Dependabot M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Dependabot
What does Dependabot do?
Dependabot is an automated dependency update tool that monitors software repositories for outdated or vulnerable dependencies and automatically creates pull requests to update them to secure versions. It scans dependencies for known security vulnerabilities and generates alerts and fix pull requests, integrating directly into GitHub's native development workflows as part of GitHub Advanced Security.
Is Dependabot a public or private company?
Dependabot is a private company. It is classified as corporate owned and is currently acquired.
When was Dependabot founded?
Dependabot was founded in 2017. It employs 11 to 50 people.
Where is Dependabot based?
Dependabot is headquartered in London, United Kingdom, in the Europe region.
How does Dependabot make money?
One revenue line is on record: gitHub Advanced Security Subscription.
Who are Dependabot's main competitors?
Direct peers on record are Renovate, Snyk, Mend (formerly WhiteSource) and Sonatype Nexus. Broad incumbents are GitLab Dependency Scanning, JFrog Xray and GitHub. Emerging players are Socket, Endor Labs and Chainguard.
Does Dependabot have an API?
No public API is recorded for Dependabot.
What industry is Dependabot in?
Dependabot's product category is Application Security. Its primary akta.pro industry code is HDADACAG, Code & Repository Security (Git Security, Code Integrity), with a secondary code of BPAKAHAJ, Application Security & DevSecOps Services. Its NAICS code is 54151 and its SIC code is 7372.