Companies that use Dependabot

Analyzed and validated by Henley Wing Chiu ยท Updated
All โ€บ devops โ€บ Dependabot

Dependabot We detected 10,140 companies using Dependabot. The most common industry is Software Development (31%) and the most common company size is 1,001-5,000 employees (33%). We find new customers by discovering URLs with known URL patterns through web crawling or certificate transparency logs. Note: We track companies that are using Dependabot in a public Github repo. We also track companies using Github Enterprise here and companies using Github (free) here

โฑ๏ธ Data is delayed by 1 month. To show real-time data, sign up for a free trial or login
Company Employees Industry Country Region Usage Start Date
Airbus 10,001+ Aviation and Aerospace Component Manufacturing
France
Europe 2026-08-25
Skatteetaten 5,001โ€“10,000 Government Administration
Norway
Europe 2026-08-17
Factory 51โ€“200 Software Development
United States
North America 2026-08-12
AVEVA 5,001โ€“10,000 Software Development
United Kingdom
Europe 2026-07-30
Splunk 5,001โ€“10,000 Software Development
United States
North America 2026-07-24
Movable Ink 501โ€“1,000 Software Development
United States
North America 2026-07-23
Teradata 10,001+ Software Development
United States
North America 2026-07-22
Ensono 1,001โ€“5,000 IT Services and IT Consulting
United States
North America 2026-07-21
Deutsche Telekom 10,001+ Telecommunications
Germany
Europe 2026-06-30
Ross Video 1,001โ€“5,000 Broadcast Media Production and Distribution
Canada
North America 2026-06-24
Eco 11โ€“50 Technology, Information and Internet
United States
North America 2026-06-23
Nexus 11โ€“50 Software Development
United States
North America 2026-06-20
bp 10,001+ Oil and Gas
United Kingdom
Europe 2026-06-19
BTC - Business Technology Consulting AG 1,001โ€“5,000 IT Services and IT Consulting
Germany
Europe 2026-06-15
Garmin 10,001+ Computers and Electronics Manufacturing
United States
North America 2026-06-12
Brain Station 23 501โ€“1,000 Software Development
United States
North America 2026-06-12
RES 1,001โ€“5,000 Services for Renewable Energy
United Kingdom
Europe 2026-06-09
Berlin Institute of Health 501โ€“1,000 Research Services
Germany
Europe 2026-06-06
IBM 10,001+ IT Services and IT Consulting
United States
North America
Showing 1-20

Market Insights

๐Ÿข Top Industries

Software Development 226 (31%)
IT Services and IT Consulting 58 (8%)
Government Administration 53 (7%)
Financial Services 44 (6%)
Technology, Information and Internet 42 (6%)

๐Ÿ“ Company Size Distribution

1,001-5,000 employees 240 (33%)
501-1,000 employees 175 (24%)
10,001+ employees 152 (21%)
5,001-10,000 employees 62 (8%)
201-500 employees 61 (8%)

๐Ÿ“Š Who usually uses Dependabot and for what use cases?

Source: Analysis of job postings that mention Dependabot (using the Bloomberry Jobs API)

Job titles that mention Dependabot
i
Job Title
Share
DevOps/DevSecOps Engineer
28%
Security Engineer/Application Security Engineer
24%
Software Engineer/Backend Engineer
15%
Platform Engineer/SRE
11%
My analysis shows that Dependabot purchasing decisions are driven primarily by engineering leadership and security teams, with Director of Engineering and Security Director roles appearing in the leadership segment. These buyers are focused on scaling secure software delivery, reducing technical debt, and embedding security into CI/CD pipelines. Their strategic priorities center on DevSecOps transformation, vulnerability management at scale, and creating developer-friendly security guardrails that don't slow down delivery velocity.

The day-to-day users are predominantly DevOps Engineers (28%) and Security Engineers (24%), with Software Engineers and Platform Engineers also heavily involved. These practitioners integrate Dependabot into their broader security scanning workflows alongside tools like Snyk, SonarQube, and Trivy. They use it for dependency management, automated pull requests for security updates, and reducing supply chain risk. I noticed these users are responsible for configuring scanning schedules, triaging findings, managing remediation workflows, and ensuring vulnerable dependencies are updated before reaching production.

The postings reveal companies are trying to accomplish shift-left security and reduce the burden on developers. Phrases like "shift security left within the software delivery platform," "automate dependency management across ecosystems," and "implement policy for compliant deployments" appear repeatedly. Organizations want to "eliminate sensitive data exposure across source code" and provide "strong supply-chain protection throughout the software development lifecycle." The emphasis on automation, developer experience, and compliance-ready delivery shows Dependabot fits into broader efforts to make security transparent and automatic rather than a manual gate.

๐Ÿ‘ฅ What types of companies use Dependabot?

Source: Analysis of Linkedin bios of 10,140 companies that use Dependabot

Company Characteristics
i
Trait
Likelihood
Funding Stage: Series E
82.9x
Funding Stage: Secondary market
82.2x
Funding Stage: Series D
40.3x
Industry: Blockchain Services
20.9x
Industry: Computer Networking Products
16.3x
Industry: Computer and Network Security
15.1x
I noticed that Dependabot users span a remarkably diverse range of technical builders. These aren't just generic "software companies." They're creating specific, tangible products: cloud infrastructure platforms like Vercel and Vultr, financial services APIs like Upvest and Verivend, privacy compliance tools like Usercentrics, voting systems like VotingWorks and Vocdoni, and developer tools like Bruno and Vellum. What unites them is that they're all building software that other businesses depend on, whether that's payment processing, data infrastructure, cybersecurity, or development platforms.

These companies cluster heavily in the growth and scale-up phase. While there are some enterprise giants like Vox Media and Utility Warehouse, and early pre-seed startups like Twill, the majority sit in that 11-200 employee range with Series A or B funding. They've proven product-market fit and are now scaling their engineering teams and customer bases. The funding amounts (typically $5M to $40M) and employee counts suggest companies past the survival stage but still growing rapidly.

๐Ÿ”ง What other technologies do Dependabot customers also use?

Source: Analysis of tech stacks from 10,140 companies that use Dependabot

Commonly Paired Technologies
i
Technology
Likelihood
2074.0x
1988.1x
I noticed that Dependabot users are almost exclusively GitHub-native engineering organizations that have adopted a security-first, infrastructure-as-code approach to software development. The overwhelming correlation with GitHub Actions (1377x more likely) and GitHub Advanced Security (2554x more likely) tells me these are companies that have committed deeply to the GitHub ecosystem rather than spreading across multiple platforms. They're building automated, scalable development workflows where security and dependency management are treated as critical engineering priorities, not afterthoughts.

The pairing of Terraform and Helm with Dependabot reveals something specific about their architecture. These companies are running cloud-native infrastructure with Kubernetes deployments and treating infrastructure as code. Dependabot fits naturally here because when you're automating infrastructure deployments, you also need automated dependency updates to prevent security vulnerabilities from creeping into your infrastructure definitions. The high correlation with Claude Code suggests these teams are also early adopters of AI coding tools, indicating they're progressive engineering organizations always looking for ways to automate and accelerate development.

The full stack reveals product-led companies in growth or scale-up stages. These aren't early startups cobbling together basic tools, nor are they enterprise giants moving slowly. They're sophisticated engineering teams building products where uptime, security, and deployment velocity matter competitively. The Verified GitHub Organization correlation indicates they care about their public developer presence, suggesting many are likely building developer tools, APIs, or infrastructure products where their GitHub profile serves as social proof.

Alternatives and Competitors to Dependabot

Explore vendors that are alternatives in this category

Bitbucket Bitbucket Cloudflare Workers Cloudflare Workers Cloud Run Cloud Run Alibaba Cloud Alibaba Cloud Supabase Supabase Hostinger Hostinger Scaleway Scaleway Vultr Vultr Heroku Heroku Huawei Cloud Huawei Cloud Jfrog Jfrog IBM Cloud IBM Cloud Google Cloud Google Cloud Oracle Cloud Oracle Cloud Gitea Gitea Infomaniak Infomaniak OVH OVH Hetzner Hetzner IONOS IONOS Buildkite Buildkite AppVeyor AppVeyor Google Cloud Build Google Cloud Build Gitlab CI Gitlab CI DigitalOcean DigitalOcean Gitlab Dedicated Gitlab Dedicated Contabo Contabo Jenkins Jenkins Gitlab Gitlab AWS AWS Azure Azure Travis CI Travis CI Azure Devops Azure Devops Dependabot Dependabot Github Github Vercel Pro Vercel Pro Github Actions Github Actions Bitrise Bitrise Cloudsmith Cloudsmith GitHub Enterprise GitHub Enterprise Github Sponsors Github Sponsors Verified Github Organization Verified Github Organization Github Enterprise with data residency Github Enterprise with data residency Github Discussions Github Discussions Helm Helm Windows Server Windows Server Azure App Service Azure App Service

Loading data...