Dependabot vs Renovate

Dependabot and Renovate are update bots. Each one opens a pull request when a dependency has a new version. This page compares them from their own docs and shows what neither one checks.

Updated 5 Oct 2026

Feature Comparison

Dependabot is the update bot built into GitHub. Renovate is an open-source bot that runs on GitHub and on many other platforms. Both open pull requests for new versions. The table lists what each project documents.

Question Dependabot Renovate
Where it runs GitHub. The docs call it a GitHub tool. GitHub, GitLab, Azure DevOps, Bitbucket Cloud and Server, Gitea, Forgejo and AWS CodeCommit. Gerrit is experimental.
How you run it Check a dependabot.yml file into the repository. Use the hosted Mend Renovate app, the npm package, or a Docker image.
Package ecosystems About 30 listed, including npm, pip, Maven, Cargo, Go modules, Docker and GitHub Actions. Many managers in groups such as JavaScript, Python, Java, Docker, Terraform, Helm and CI. The docs give no total.
Update schedule Daily, weekly, monthly, quarterly, semiannually, yearly or cron. Schedules that limit when pull requests appear.
Wait before a new release A cooldown of 3 days is the default for version updates. Security updates skip it. The minimumReleaseAge option. A preset waits 3 days for an npm package.
Automerge Set up with a GitHub Actions workflow and gh pr merge --auto. Built in. Off by default.
Overview page of pending updates Not described in the version updates docs. The Dependency Dashboard, an issue in your repository.
Security updates Yes. Driven by Dependabot alerts and the GitHub Advisory Database. Yes. An option reads the OSV database, which Renovate downloads and queries offline.
Flags a malicious update Not described in the docs Vigilance read. Experimental. It uses OSV data and skips updates marked malicious.
Licence and cost Part of GitHub. The docs Vigilance read state no price. AGPL-3.0-only. A free Community app exists. Enterprise is paid.

Sources: the GitHub docs on version updates, supported ecosystems and options, and the Renovate docs on the home page, configuration options and security presets. The Mend pricing page lists Mend Renovate Enterprise at up to $250 per developer per year.

The main difference is reach. If all your code sits on GitHub, Dependabot needs no install. If you use GitLab, Bitbucket or Azure DevOps, only Renovate fits. If you want a lot of control over grouping, schedules and merging, Renovate gives you more settings. Dependabot gives you fewer settings and less to maintain.

Dependabot has limits you can set in its file. It opens at most 5 version update pull requests at one time by default. Security update pull requests do not count toward that limit. It also pauses itself when maintainers stop reacting to its pull requests.

Using Dependabot and Renovate with GitHub Actions

Both bots can update the actions in your workflow files. This matters because an action runs inside your build with access to its secrets.

Dependabot needs three settings for this. They are the github-actions ecosystem, the directory /, and a schedule. This is the example from the GitHub docs:

version: 2
updates:
  - package-ecosystem: "github-actions"
    directory: "/"
    schedule:
      interval: "weekly"

Dependabot then opens a pull request for each outdated action. It also covers reusable workflows used inside your workflows. GitHub docs say Dependabot raises security update pull requests for vulnerable actions too.

Renovate finds workflow files on its own. It reads files in .github/workflows and files named action.yml. It handles semantic versions, floating tags such as v4, and branches. It can also update tool versions in the with: input of more than 80 supported actions.

Renovate has one extra setting that matters here. The preset helpers:pinGitHubActionDigests pins each action to a full commit hash. A line then looks like this:

uses: actions/checkout@3df4ab11eba7bda6032a0b82a6bb43b11571feac # v4.0.0

A pinned hash cannot move. This matters because of a real case. In March 2025 an attacker repointed tags of tj-actions/changed-files to malicious code. The GitHub advisory lists versions up to 45.0.7 as affected. The code read secrets from memory and wrote them to build logs. A workflow that used a tag ran the new code. A workflow that used a full hash did not. Read the record on the attack page.

A pin does not finish the job. When the bot opens a pull request for the next action version, you must decide whether to merge it. That brings us to the gap in both bots.

What Neither Bot Checks in the Update It Opens

Neither bot reads the files in the new version to see what they can now do. Their docs describe checks on version numbers, advisory databases and release age. They do not describe a check on the content of the update.

Each bot does help. Both can wait before they open a pull request. The Renovate security preset for npm explains why. The wait gives "malware researchers and scanners" time to find bad behaviour in a package. Dependabot applies a 3-day cooldown to version updates by default. Renovate can also use OSV data to skip an update that OSV marks as malicious. Renovate calls this feature experimental.

These checks all depend on someone else finding the problem first. A wait only works if a researcher reports the release inside the wait. An advisory database only helps after a report exists. A brand-new attack has no report on its first day.

The axios case in March 2026 shows both sides. Huntress reports that axios 1.14.1 and 0.30.4 stayed on npm for about three hours. Both added a new dependency called plain-crypto-js with a postinstall script that installed a remote access trojan. A 3-day wait keeps those versions out of a bot pull request. A bot with no wait can open the pull request inside that window. A change to that dependency list was visible in the files. Read the axios record for the full case.

Vigilance fills this gap. It compares the version you trust with the version in the pull request. It reports each file that gained a new capability, such as a hidden install step or a new network call. On the axios update it reports one file:

vigi diff --old ./axios-1.14.0 --new ./axios-1.14.1

HEADS UP. 1 file changed. package.json can now run a hidden helper on install and reach the network.

Vigilance has limits, and you must know them. It does not open pull requests. It does not update anything. It is not a scanner for known bugs, so it does not replace Dependabot alerts or the Renovate OSV option. It does not replace a wait either. A wait and Vigilance work together, because each one catches a different case. A wait helps when researchers are quick. Vigilance helps when nobody has reported the change yet.

Stay in the flow you have. Keep the bot. Check out the old and the new version into two folders, run vigi diff on them, and read the result before you merge. Most days Vigilance shows nothing. It stays quiet on normal updates. Pro runs with no network connection. See the attack library for 110 real cases, or compare tools for software supply chain security.

Which One to Pick

Pick Dependabot if your code is on GitHub and you want the shortest path. You add one file and it works. It fits small teams and repositories with few special rules.

Pick Renovate if you use more than GitHub, or if you want fine control. It runs on GitLab, Azure DevOps, Bitbucket and more. It has a Dependency Dashboard, built-in automerge and shared presets. Self-hosting is possible, and the Community app is free. The cost is more configuration to learn and keep up to date.

Whichever bot you pick, add three habits. First, set a wait on new releases. Second, pin your GitHub Actions to full commit hashes. Third, check what changed in an update before you merge it. The first two reduce risk. The third catches what the first two miss.

Common Questions

What is the difference between Dependabot and Renovate?

Dependabot is built into GitHub and runs from a dependabot.yml file. Renovate also runs on GitLab, Azure DevOps, Bitbucket and others, and has more settings. Both open pull requests for dependency updates.

Does Dependabot work with GitHub Actions?

Yes. Dependabot supports GitHub Actions for version updates and security updates. Add the github-actions ecosystem to dependabot.yml and it opens pull requests for outdated actions.

Is Renovate free?

Renovate is open source under the AGPL-3.0-only licence. Mend offers a free cloud-hosted Community app for GitHub.com and Bitbucket Cloud. Mend Renovate Enterprise is a paid product.

Can Dependabot or Renovate stop a malicious package?

Only in part. Both can wait a few days before they open a pull request, which gives researchers time to find a bad release. Neither reads the files in the new version to see what they can now do.

Can I run Vigilance on a Dependabot or Renovate pull request?

Yes. Vigilance compares the version you trust with the version in the pull request and reports any file that gained a new capability. It does not open pull requests and it does not replace either bot.

Try It on Your Own Software.

Show it the version you run today and the one you are about to install.

Download Vigilance See Pricing