Skip to content
Change the repository type filter

All

    Repositories list

    • 🤖 Dependabot's core logic for creating update PRs.
      Ruby
      1.2k5.2k1.2k139Updated Sep 17, 2025Sep 17, 2025
    • cli

      Public
      A tool for testing and debugging Dependabot update jobs.
      Go
      62341176Updated Sep 16, 2025Sep 16, 2025
    • Extract information about the dependencies being updated by a Dependabot-generated PR.
      TypeScript
      952582311Updated Sep 14, 2025Sep 14, 2025
    • A collection of manifest files for various package managers and is used to perform end-to-end tests for Dependabot.
      HCL
      3954313Updated Sep 3, 2025Sep 3, 2025
    • demo

      Public template
      🤖 Fork me to try out Dependabot
      Ruby
      3.5k25258Updated Aug 26, 2025Aug 26, 2025
    • Shell
      3500Updated Aug 1, 2025Aug 1, 2025
    • Demonstrates how to self-host Dependabot :dependabot:
      Shell
      141804Updated May 8, 2025May 8, 2025
    • dependabot-script

      Public archive
      Ruby
      27556207Updated May 8, 2025May 8, 2025
    • goproxy

      Public archive
      An HTTP proxy library for Go. Dependabot uses this in our internal credential proxy: https://github.com/dependabot/dependabot-core/?tab=readme-ov-file#private-registry-credential-management We maintain a fork in case the original goes down or if we need to run additional patches on top.
      Go
      1.2k1301Updated Mar 13, 2025Mar 13, 2025
    • git-shim

      Public
      git https shim
      Go
      72111Updated Jun 16, 2024Jun 16, 2024
    • .github

      Public
      191800Updated Apr 29, 2024Apr 29, 2024
    • yarn-lib

      Public
      A build of yarn that provides access to its internals
      Shell
      181600Updated Apr 17, 2024Apr 17, 2024
    • Old example workflow for updating Dependabot pull requests. No longer relevant, see Readme for details.
      Ruby
      193501Updated May 12, 2023May 12, 2023
    • Dummy packages for testing Dependabot
      Ruby
      121700Updated May 12, 2023May 12, 2023
    • updater-action

      Public archive
      Runs Dependabot Updates via GitHub Actions. This fork exists because the Action used to live in the Dependabot org prior to GA. So beta customers may still depend on its original location.
      TypeScript
      57700Updated Oct 7, 2022Oct 7, 2022
    • Jupyter notebook for a blog post on gem vulnerabilities and version updates.
      Jupyter Notebook
      42100Updated Sep 6, 2022Sep 6, 2022
    • Ruby
      2804Updated Aug 9, 2022Aug 9, 2022
    • Old database of Elixir security advisories before the GitHub Security Advisory DB supported Hex / Elixir.
      Ruby
      915110Updated Jul 22, 2022Jul 22, 2022
    • gomodules-extracted

      Public archive
      This code was originally used in dependabot-core, but has since been removed. See Readme for details.
      Go
      101700Updated Nov 24, 2021Nov 24, 2021
    • api-docs

      Public archive
      [Deprecated] Documentation for Dependabot Preview's API
      204030Updated Jul 29, 2021Jul 29, 2021
    • feedback

      Public archive
      The old feedback repository for Dependabot. Click below for the new repository.
      299400Updated Jun 29, 2020Jun 29, 2020
    • vgotest

      Public
      A dummy Go Module for testing Dependabot.
      31010Updated May 20, 2020May 20, 2020
    • monolog

      Public
      A fork of "Seldaek/monolog" used for dependabot-core tests
      PHP
      1.9k700Updated Aug 27, 2019Aug 27, 2019
    • A dummy PHP package for testing Dependabot.
      31000Updated Jun 8, 2017Jun 8, 2017
    • A dummy PHP package for testing Dependabot.
      41200Updated Jun 8, 2017Jun 8, 2017