Best Dependabot MCP Servers
Dependabot is a GitHub service that automates dependency updates in software projects by creating pull requests when new versions of dependencies are available, helping developers keep their projects secure and up-to-date.
Why this server?
Configures Dependabot for automated dependency updates in the generated project.
AlicenseAqualityAmaintenanceBackGen's MCP server lets AI assistants scaffold production-ready Express.js + TypeScript backend projects with your choice of ORM (Prisma, Drizzle, Mongoose), install auth/payment/storage plugins, generate CRUD resources, and run health checks — all through natural language conversation.Last updated101554MITWhy this server?
Surfaces security alerts and CVE warnings by integrating with Dependabot and the GitHub Advisory Database.
AlicenseBqualityDmaintenanceProvides crowdsourced package intelligence and security alerts for AI coding assistants by analyzing project dependencies and framework co-occurrence. It enables automated project scans, package alternative discovery, and data-driven recommendations across multiple programming ecosystems.Last updated1046MITWhy this server?
Gates Dependabot bump PRs by replaying recorded skill workflows against the updated dependency, detecting drifts in tool-call behavior without LLM calls.
AlicenseAqualityBmaintenanceRecord an agent's MCP tool-call workflow once, replay it deterministically for zero tokens, and get a receipt — a snapshot-testing and deterministic-execution layer for Agent Skills.Last updated59531MITWhy this server?
Integrates Dependabot vulnerability alerts for security triage and risk assessment.
AlicenseAqualityBmaintenanceEnables AI coding agents to orchestrate the full software development lifecycle on GitHub, including planning, issue creation, code review, security triage, and release readiness checks.Last updated132131MITWhy this server?
Dependabot is used for automatic security updates of dependencies.
AlicenseAqualityDmaintenanceProvides access to 5,000+ Key Performance Indicators across 264 operating areas for all Swedish municipalities and regions, enabling statistical analysis, comparisons, and trend tracking of Swedish public sector data.Last updated213712MITWhy this server?
Provides automated triage for Dependabot alerts and pull requests as part of a headless workflow for maintaining open-source repositories.
AlicenseAqualityCmaintenanceOpen source contribution manager — tracks PRs across repos, discovers contributable issues, diagnoses CI failures, and drafts maintainer responses. 21 MCP tools, 5 resources, 3 prompts. Ships as CLI, MCP server, and Claude Code plugin.Last updated2011MITWhy this server?
Scans repository dependencies for security updates using Dependabot CLI, identifying vulnerable packages from ecosystem security advisories.
AlicenseAqualityCmaintenanceAI-powered security code review for Claude Code that runs multiple scanners (CodeQL, Semgrep, etc.) to detect vulnerabilities, secrets, and dependency CVEs, producing prioritized reports.Last updated23MITWhy this server?
Checks Dependabot alerts and dependency vulnerabilities, including unfixed critical alerts and supply chain risks across repositories.
AlicenseAqualityDmaintenanceAn MCP server that enables AI agents to perform comprehensive GitHub security audits across org settings, repositories, Actions workflows, secrets, supply chain, and access control using 39 tools and 45 checks.Last updated3928411MITWhy this server?
Enables querying of Dependabot alerts for GitHub repositories, providing visibility into dependency vulnerabilities
AlicenseBqualityFmaintenanceThis server integrates with GitHub Advanced Security to load security alerts and bring it into your context. Supports Dependabot Security Alerts, Secret Scanning Alerts, Code Security AlertsLast updated3295MIT