Skip to main content

Category

Dependabot in production: dependabot.yml, security updates, auto-merge and troubleshooting

Dependabot is not something you switch on and forget. Value comes from separating its three jobs — detection via alerts, remediation via security updates, and freshness via version updates — then structurally containing the flood of pull requests and running the whole thing against an SLA. The pillar covers the overall shape, enablement and billing (standard runners do not consume Actions minutes); the spokes work through dependabot.yml option by option.

12 articles in total

Foundational guide

Foundational guide (start here)

Dependabot
GitHub Actions
サプライチェーンセキュリティ
依存関係管理
DevSecOps

Dependabot production-operations guide: separate alerts, security updates, and version updates into the 'three pillars' to keep dependencies automatically and safely up to date

An implementation guide to operating GitHub's Dependabot at production quality. Faithful to the official documentation (as of June 2026), it explains — with copy-pasteable real code and a project viewpoint — the differences and proper use of the three pillars (Dependabot alerts / security updates / version updates), how to enable them, practical dependabot.yml settings, where it runs (Actions runners) and billing, auto-merge and grouping, and operations design with an SLA.

12 min read

Related practical articles