A friendly @GitHub-native robot that helps you keep your dependencies up to date

Joined May 2017
59 Photos and videos
If we shipped version update cooldowns as a default, would you want it on, and what should the default be?
0% Yes, default 1 day
14% Yes, default 3 days
86% Yes, default 7 days
0% No, default 0 days
7 votes • 1 day
1
114
Jalen Brunson is the Dependabot of the NBA
48
Dependabot retweeted
Dependabot now supports Deno 🚀 Add package-ecosystem: "deno" to your dependabot.yml and start getting automated dependency update PRs. Nice addition from @GitHub @deno_land
1
6
120
Dependabot retweeted
Just published an episode about Nix support in Dependabot with Ankit Kumar Honey, senior engineering manager at GitHub, working on the Dependabot ecosystem, and Jamie Magee, principal software engineer at Microsoft, focusing on open source software and supply chain security, who contributed the Dependabot Nix support recently. Bump bump bump. fulltimenix.com/episodes/dep…
1
2
5
747
It's been a minute, but I'm back on X, and I'll be around here more often. See you in the tags and comments!!
4
10
735
Dependabot retweeted
Dependabot support for uv just went GA 🎉🎉🎉
6
22
301
10,996
Dependabot retweeted
Do you use the bun package manager and dependabot? If so, you might want to try the experimental support for bun in dependabot. Add `enable-beta-ecosystems: true` to your `dependabot.yml` and add the `npm` package ecosystem. You can see an example below. Let me know if you try this!
3
3
19
3,445
🚀 @github Dependabot can now use the power of @GitHubCopilot to fix breaking changes introduced by Dependabot updates! To learn more and join the waitlist, check out the blog: github.blog/changelog/2024-1… #dependabot #copilot #autofix #appsec #ghas #security #GitHubUniverse

1
1
4
934
Dependabot retweeted
🚀@github can now leverage @MSFTCopilot to auto-magically fix your code if there are any breaking changes introduced by a @dependabot update. only supports #typescript for now but this will be huge github.blog/changelog/2024-1… #appsec #cybersecurity #githubuniverse2024

1
1
380
Dependabot retweeted
3 Jul 2024
Replying to @forstmeier
don’t hate the player hate the weekly openssh CVE game
1
2
300
Dependabot retweeted
Five years ago today, we were at GitHub Satellite Berlin announcing that GitHub acquired @dependabot . In the time since, Dependabot has helped secure the software supply chain for millions of developers across the world by creating automatic fixes for vulnerable dependencies.
2
8
40
8,448
Dependabot retweeted
I just found out you can group @dependabot updates 🤯 No more "25 open pull requests". Just put these lines into your dependabot.yml:
1
4
35
5,448
Dependabot retweeted
7 May 2024
You can now run Dependabot as a GitHub Actions workflow! 🌟 Read more about the benefits this unlocks, including self-hosted runner support. github.blog/2024-05-02-depen…
4
33
133
84,954