#dependabot
CLAUDE: You can validate and test your dependabot config locally by installing dependabot cli "gh extension install github/gh-dependabot"

ME: "Could not find extension 'github/gh-dependabot' on host github.com"

CLAUDE: My apologies - that extension doesn't exist. I gave you incorrect information.
October 8, 2025 at 3:20 PM
holy shit hell froze over and GitHub added uv.lock support to Dependabot: github.com/dependabot/d...
Support updating `uv.lock` · Issue #10478 · dependabot/dependabot-core
Is there an existing issue for this? I have searched the existing issues Feature description Now that uv has a lockfile, it would be nice if dependabot supported making updates to pyproject.toml an...
github.com
March 1, 2025 at 9:38 AM
Release Engineer (approves & merges Dependabot PRs)
September 22, 2026 at 4:25 PM
2 beautiful women named "renovate" and "dependabot" messaging me
November 24, 2025 at 8:52 AM
And then dependabot wakes up.

DAMN YOU.
September 25, 2026 at 1:11 AM
What's hilarious, after it gave the answer about extension that doesn't exist - it provided detailed instructions how to use it.
October 8, 2025 at 3:36 PM
I just shipped .NET SDK updates for Dependabot 🎉

#dependabot #dotnet #github

github.blog/changelog/20...
Dependabot can now perform version updates for the .NET SDK · GitHub Changelog
Dependabot can now perform version updates for the .NET SDK
github.blog
November 19, 2024 at 10:01 PM
Dependabot security alerts have terrible signal-to-noise ratio, especially for Go vulns. That hurts security!

Just turn it off and set up a pair of scheduled GitHub Actions, one running govulncheck and the other running CI with the latest version of your deps.

Less work, less risk, better results!
Turn Dependabot Off
I recommend turning Dependabot off and replacing it with a pair of scheduled GitHub Actions, one running govulncheck, and the other running CI against the latest version of your dependencies.
words.filippo.io
February 20, 2026 at 7:56 PM
dependabot supporting nix flakes was an unexpected surprise announcement
April 7, 2026 at 2:52 PM
Dependabot still doesn't support pnpm v11. Upvote this issue please: github.com/dependabot/d...
Support PNPM v11 · Issue #14794 · dependabot/dependabot-core
Is there an existing issue for this? I have searched the existing issues Feature description PNPM vesrion 11 is in release candidate stage, and I would like to use it in my project. However, I see ...
github.com
August 11, 2026 at 9:27 AM
currently a very useful dependabot config
February 16, 2026 at 9:10 AM
GitHub should worry less about “dependabot” and focus more on how the internet “depends a lot” on their basic functionality
August 21, 2026 at 1:12 AM
the best release!

get going dependabot 🎉
July 8, 2026 at 4:37 PM
dependabot is actually so noisy it becomes harmful
June 15, 2026 at 6:42 PM
dependabot notifications
Spirited Away: No-Face in the Ocean Wave
Alt: Spirited Away: No-Face in the Ocean Wave
static.klipy.com
August 21, 2026 at 10:24 PM
Me uploading a few of my old old hobby projects to GitHub just to keep them somewhere.

Dependabot:
March 17, 2026 at 8:39 AM
Dependabot went brrrr overnight.

Merge those updates to the dotnet setup action folks.
December 27, 2024 at 12:47 PM
No dependabot, bad dependabot, you can’t update codeql bit by bit. You break it.
July 28, 2026 at 2:47 AM
a beautiful woman named dependabot alerts won’t stop emailing me
December 10, 2024 at 8:46 PM
never understood ghosting until I met dependabot
March 25, 2024 at 7:27 PM
I really wish dependabot was smarter.

If I'm targeting .NET 8 as a runtime don't tell me to update all my runtime dependencies to v9.
November 27, 2024 at 1:31 PM
It's, uh, less than ideal that I'm allowed to claim a GitHub username like this.
March 23, 2026 at 6:01 PM
You can negate operators, searching for “-author:app/dependabot” will hide dependabot PRs
March 9, 2026 at 5:56 PM
Me in the afterlife: woah, so peaceful. I’m so happy to be h…

Over the loudspeaker:
DEPENDABOT: THIS AUTOMATED PULL REQUEST FIXES A SECURITY VUNERABILITY (MODERATE SEVERITY)
June 23, 2023 at 1:45 PM