Companies that use Dependabot

Analyzed and validated by Henley Wing Chiu
All ‹ devops ‹ Dependabot

Dependabot We detected 6,804 companies using Dependabot. The most common industry is Software Development (35%) and the most common company size is 2-10 employees (40%). We find new customers by discovering URLs with known URL patterns through web crawling or modifications to subprocessor lists. Note: We track companies that are using Dependabot in a public Github repo. We also track companies that are using Github here

⏱ïļ Data is delayed by 1 month. To show real-time data, sign up for a free trial or login
Company Employees Industry Country Region Usage Start Date
cyberviserai.com 2–10 N/A N/A N/A
ZÞs 11–50 IT Services and IT Consulting
US United States
North America
0G 51–200 Technology, Information and Internet
KY KY
North America
Bloctopus 2–10 Blockchain Services
GB United Kingdom
Europe
Intuition 11–50 Technology, Information and Internet
PR PR
North America
0xkato 2–10 N/A N/A N/A
Miden 11–50 Blockchain Services N/A N/A
Playgrounds 2–10 Software Development
US United States
North America
Ethernal 11–50 Software Development
RS RS
Europe
Privado ID (Formerly Polygon ID) 11–50 Technology, Information and Internet
ID Indonesia
N/A
0x 51–200 Software Development
US United States
North America
raduan.xyz 2–10 N/A N/A N/A
Horizon 51–200 Technology, Information and Internet
CA Canada
North America
10Pines 51–200 Software Development
AR Argentina
South America
10up 201–500 Technology, Information and Internet
OO OO
Europe
ElasticPress.io 2–10 N/A N/A N/A
10x Genomics 1,001–5,000 Biotechnology Research
US United States
North America
128 Technology 51–200 IT Services and IT Consulting
US United States
North America
15Five 201–500 Software Development
US United States
North America
Humara 51–200 Software Development
GB United Kingdom
Europe
Showing 1-20

Market Insights

ðŸĒ Top Industries

Software Development 1666 (35%)
Technology, Information and Internet 593 (13%)
IT Services and IT Consulting 578 (12%)
Government Administration 191 (4%)
Computer and Network Security 172 (4%)

📏 Company Size Distribution

2-10 employees 2658 (40%)
11-50 employees 1570 (23%)
51-200 employees 1122 (17%)
201-500 employees 506 (8%)
501-1,000 employees 271 (4%)

📊 Who usually uses Dependabot and for what use cases?

Source: Analysis of job postings that mention Dependabot (using the Bloomberry Jobs API)

Job titles that mention Dependabot
i
Job Title
Share
DevOps/DevSecOps Engineer
28%
Security Engineer/Application Security Engineer
24%
Software Engineer/Backend Engineer
15%
Platform Engineer/SRE
11%
My analysis shows that Dependabot purchasing decisions are driven primarily by engineering leadership and security teams, with Director of Engineering and Security Director roles appearing in the leadership segment. These buyers are focused on scaling secure software delivery, reducing technical debt, and embedding security into CI/CD pipelines. Their strategic priorities center on DevSecOps transformation, vulnerability management at scale, and creating developer-friendly security guardrails that don't slow down delivery velocity.

The day-to-day users are predominantly DevOps Engineers (28%) and Security Engineers (24%), with Software Engineers and Platform Engineers also heavily involved. These practitioners integrate Dependabot into their broader security scanning workflows alongside tools like Snyk, SonarQube, and Trivy. They use it for dependency management, automated pull requests for security updates, and reducing supply chain risk. I noticed these users are responsible for configuring scanning schedules, triaging findings, managing remediation workflows, and ensuring vulnerable dependencies are updated before reaching production.

The postings reveal companies are trying to accomplish shift-left security and reduce the burden on developers. Phrases like "shift security left within the software delivery platform," "automate dependency management across ecosystems," and "implement policy for compliant deployments" appear repeatedly. Organizations want to "eliminate sensitive data exposure across source code" and provide "strong supply-chain protection throughout the software development lifecycle." The emphasis on automation, developer experience, and compliance-ready delivery shows Dependabot fits into broader efforts to make security transparent and automatic rather than a manual gate.

ðŸ‘Ĩ What types of companies use Dependabot?

Source: Analysis of Linkedin bios of 6,804 companies that use Dependabot

Company Characteristics
i
Trait
Likelihood
Funding Stage: Series E
82.9x
Funding Stage: Secondary market
82.2x
Funding Stage: Series D
40.3x
Industry: Blockchain Services
20.9x
Industry: Computer Networking Products
16.3x
Industry: Computer and Network Security
15.1x
I noticed that Dependabot users span a remarkably diverse range of technical builders. These aren't just generic "software companies." They're creating specific, tangible products: cloud infrastructure platforms like Vercel and Vultr, financial services APIs like Upvest and Verivend, privacy compliance tools like Usercentrics, voting systems like VotingWorks and Vocdoni, and developer tools like Bruno and Vellum. What unites them is that they're all building software that other businesses depend on, whether that's payment processing, data infrastructure, cybersecurity, or development platforms.

These companies cluster heavily in the growth and scale-up phase. While there are some enterprise giants like Vox Media and Utility Warehouse, and early pre-seed startups like Twill, the majority sit in that 11-200 employee range with Series A or B funding. They've proven product-market fit and are now scaling their engineering teams and customer bases. The funding amounts (typically $5M to $40M) and employee counts suggest companies past the survival stage but still growing rapidly.

🔧 What other technologies do Dependabot customers also use?

Source: Analysis of tech stacks from 6,804 companies that use Dependabot

Commonly Paired Technologies
i
Technology
Likelihood
2554.8x
2074.0x
1988.1x
1377.5x
491.3x
381.6x
I noticed that Dependabot users are almost exclusively GitHub-native engineering organizations that have adopted a security-first, infrastructure-as-code approach to software development. The overwhelming correlation with GitHub Actions (1377x more likely) and GitHub Advanced Security (2554x more likely) tells me these are companies that have committed deeply to the GitHub ecosystem rather than spreading across multiple platforms. They're building automated, scalable development workflows where security and dependency management are treated as critical engineering priorities, not afterthoughts.

The pairing of Terraform and Helm with Dependabot reveals something specific about their architecture. These companies are running cloud-native infrastructure with Kubernetes deployments and treating infrastructure as code. Dependabot fits naturally here because when you're automating infrastructure deployments, you also need automated dependency updates to prevent security vulnerabilities from creeping into your infrastructure definitions. The high correlation with Claude Code suggests these teams are also early adopters of AI coding tools, indicating they're progressive engineering organizations always looking for ways to automate and accelerate development.

The full stack reveals product-led companies in growth or scale-up stages. These aren't early startups cobbling together basic tools, nor are they enterprise giants moving slowly. They're sophisticated engineering teams building products where uptime, security, and deployment velocity matter competitively. The Verified GitHub Organization correlation indicates they care about their public developer presence, suggesting many are likely building developer tools, APIs, or infrastructure products where their GitHub profile serves as social proof.

Alternatives and Competitors to Dependabot

Explore vendors that are alternatives in this category

Bitbucket Bitbucket Cloud Run Cloud Run Cloudflare Workers Cloudflare Workers Alibaba Cloud Alibaba Cloud Supabase Supabase Hostinger Hostinger Google Cloud Build Google Cloud Build Scaleway Scaleway Vultr Vultr Vercel Pro Vercel Pro Heroku Heroku Huawei Cloud Huawei Cloud Bitrise Bitrise Jfrog Jfrog Cloudsmith Cloudsmith IBM Cloud IBM Cloud Gitlab CI Gitlab CI Google Cloud Google Cloud Drone CI Drone CI Oracle Cloud Oracle Cloud Buildkite Buildkite AppVeyor AppVeyor Gitea Gitea Travis CI Travis CI Infomaniak Infomaniak OVH OVH Hetzner Hetzner IONOS IONOS Contabo Contabo AWS AWS DigitalOcean DigitalOcean Azure Azure Jenkins Jenkins Gitlab Gitlab Github Actions Github Actions Verified Github Organization Verified Github Organization GitHub Enterprise GitHub Enterprise Github Github Dependabot Dependabot Github Enterprise with data residency Github Enterprise with data residency Azure Devops Azure Devops Helm Helm Windows Server Windows Server

Loading data...