Starts at
Free plan
Free, independent software advice for Indian businesses
For software companies: reach Indian businesses ready to buy

Dependabot is free and built into GitHub. It is not a separate product you buy — it is included on every GitHub plan, starting with the free one, and there is no Dependabot price list.
It does three things: alerts you when a dependency has a known vulnerability, opens pull requests to patch those vulnerabilities (security updates), and opens pull requests to keep dependencies current even when they are not vulnerable (version updates).
GitHub's own pricing page lists Dependabot security and version updates as included on the Free plan, alongside Team and Enterprise.
Dependabot runs on GitHub Actions, but GitHub's billing documentation explicitly states that use of standard GitHub-hosted runners is free for Dependabot — so it does not eat your Actions minutes.
What works well
What to watch out for
Best suited for: Any team already hosting code on GitHub — there is no reason not to turn it on · Small teams and Indian startups who need supply-chain security with no budget · Open-source maintainers keeping dependencies current across many repositories · Teams that want vulnerability patches to arrive through the normal pull-request review flow
Analysing Dependabot — pricing, features, reviews and alternatives…
Generated by App Advisor's native engine from this listing's verified data — not a paid placement.
Researched from Dependabot's official product pages · updated September 2026.
Dependabot alerts
Dependabot security updates
Dependabot version updates
Configuration and control
AI capabilities
Every edition as published by the vendor. Prices exclude GST unless stated. Full Dependabot pricing breakdown
GitHub Free
$0
per month
GitHub Team
$4
per user/month (GitHub's pricing page shows this as a first-12-months rate)
GitHub Enterprise
From $21
per user/month (GitHub's pricing page shows this as a first-12-months starting rate)
Other pricing options & add-ons
Ways to implement
Alerts and security updates are a settings toggle. Adding version updates is a single configuration file. GitHub does not publish an implementation timeline, so none is quoted.
Integrations
Security & compliance
For Indian businesses
Support & learning
Best choice if you are…
Look elsewhere if you are…
Alternatives, the same vendor's other products and India-first picks.
Yes. Dependabot is free and built into GitHub — it is not a separate product. GitHub's pricing page lists Dependabot security and version updates as included on the GitHub Free plan ($0/month), as well as on Team and Enterprise. There is no Dependabot licence, subscription or add-on to buy.
No. Dependabot itself costs nothing on any GitHub plan, including the free one, and that includes private repositories. The only money involved is whatever you already pay GitHub for your plan, and Dependabot does not add to it.
There is no Dependabot pricing, because Dependabot is not sold separately. It is a GitHub feature included on every plan. GitHub's own plan prices are $0/month for Free, $4/user/month for Team and from $21/user/month for Enterprise (the Team and Enterprise figures are shown as first-12-months rates), but Dependabot is included at every one of those tiers.
No. Dependabot runs on GitHub Actions, but GitHub's Actions billing documentation explicitly states that the use of standard GitHub-hosted runners is free for Dependabot. So Dependabot's own runs do not consume your monthly Actions quota, regardless of repository visibility. Your own CI workflows that run on Dependabot's pull requests do consume minutes in the normal way.
Alerts notify you that a dependency has a known vulnerability, matched against the GitHub Advisory Database by scanning your default branch. Security updates go a step further and automatically open pull requests upgrading those vulnerable dependencies to secure versions. Version updates are broader still — automated pull requests that keep dependencies current even when they have no vulnerabilities, configured through a dependabot.yml file.
You check a dependabot.yml configuration file into your repository, normally at .github/dependabot.yml. The file specifies where your manifest and package definition files live so Dependabot can identify outdated dependencies. You can also set a cooldown period before Dependabot considers a new release, which defaults to 3 days.
Yes — GitHub's pricing page lists Dependabot security and version updates on the Free plan, which itself includes unlimited public and private repositories. This is notably more generous than GitHub's other security features: code scanning, secret scanning, push protection and CodeQL are limited to public repositories on the Free and Team plans and only fully available on private repos with Enterprise.
Partly. Dependabot security updates already open pull requests that bump vulnerable dependencies to safe versions without any AI. Separately, GitHub documents that Dependabot alerts can be assigned to AI agents such as Copilot or Claude when enabled, and those agents can create a session and open a draft pull request with a proposed fix. The AI agent entitlement is priced separately from Dependabot, which remains free.
Dependabot is devops, ci/cd & monitoring by GitHub. Dependency updates.
Dependabot is free to use.
Yes — Dependabot offers a free plan you can start with.
No. Dependabot is developed by GitHub in San Francisco, United States, though it is used by Indian businesses.
Dependabot suits startup, small business, smb buyers looking for devops, ci/cd & monitoring.
Popular alternatives in devops, ci/cd & monitoring include Site24x7, ManageEngine Applications Manager, ManageEngine OpManager. Use App Advisor's compare tool to see them side by side.
Dependabot is available as a cloud (SaaS) product, with web access.

GitHub · San Francisco, United States · Founded 2008 · 5 products in our catalogue
Get an instant demo