Blog
3 min read

Dependabot Explained: Automatic Security and Version Updates on GitHub

Dependabot watches your project's dependencies, alerts you to known vulnerabilities and opens pull requests to update them. The three features (alerts, security updates, version updates), a dependabot.yml example with grouping and cooldowns, and how to handle the PRs without drowning.

Your app depends on dozens or hundreds of packages, and every so often a security hole is found in one of them. Dependabot is GitHub's built-in tool that notices and helps you update. (What are npm and package.json?)

It has three separate features.

1. Dependabot alerts

GitHub compares your dependency files (package-lock.json, requirements.txt, Gemfile.lock and many more) against its database of known vulnerabilities. If you use an affected version, you get an alert in the repository's Security tab, with severity and the fixed version.

Turn on in Settings → Code security. It's free for all repositories.

2. Dependabot security updates

When there's an alert and a fixed version exists, Dependabot opens a pull request that upgrades the vulnerable package to the minimum safe version. You review, check CI passes, and merge.

Also enabled in Settings → Code security.

3. Dependabot version updates

Separately, Dependabot can keep all dependencies up to date on a schedule — not just vulnerable ones. Configure it with a file at .github/dependabot.yml:

version: 2
updates:
  - package-ecosystem: "npm"
    directory: "/"
    schedule:
      interval: "weekly"
    groups:
      minor-and-patch:
        update-types: ["minor", "patch"]
    cooldown:
      default-days: 7
    open-pull-requests-limit: 5

  - package-ecosystem: "github-actions"
    directory: "/"
    schedule:
      interval: "monthly"
  • groups — combine many small updates into one PR instead of twenty.
  • cooldown — wait until a release has been out a few days before proposing it. Malicious package versions are usually caught and removed within hours or days, so a short delay is a cheap defence. (npm supply chain security)
  • github-actions — keep the actions in your workflows updated too.

Check GitHub's documentation for the current configuration options.

Handling the pull requests

Dependabot PRs pile up if you ignore them. A sustainable routine:

  1. Have CI with tests. A Dependabot PR is only as safe as the checks it runs. If the tests pass, a patch update is usually safe to merge. (Set up CI with GitHub Actions)
  2. Merge security updates promptly.
  3. Batch the rest weekly — grouped minor/patch updates in one go.
  4. Handle major versions deliberately. A major version can contain breaking changes; read the changelog before merging. (Semantic versioning explained)
  5. Close what you won't take, with a comment like @dependabot ignore this major version.

AI coding tools are good at the tedious part of a breaking upgrade — reading the migration guide and updating code to match. (How to update dependencies safely)

Dependabot vs npm audit

npm audit checks the same kind of vulnerability data locally. Dependabot does it automatically in GitHub and opens PRs. Use both: audit locally while working, Dependabot as the safety net. (npm audit explained)

Dependabot vs Renovate

Renovate is a popular alternative with more configuration options (scheduling, auto-merge rules, monorepo support) and supports more platforms than GitHub. Dependabot is simpler and built in. Either is far better than nothing.

Not every alert is urgent

Alerts are about a vulnerable package, not proof your app is exploitable. A vulnerability in a dev-only tool, or in a function your code never calls, is lower risk. Use the severity and the advisory details to prioritise — but don't let alerts sit forever.


EasySpawn keeps your server's operating system patched for you, and Claude Code can work through your Dependabot PRs — reading changelogs and fixing breaking changes — while you review. See how it works or join the waitlist.

Related: How to Update Your App's Dependencies Safely · npm audit Explained · npm Supply Chain Security · GitHub Secret Scanning

Keep reading