Cost / License
- Free
- Open Source (MIT)
Application type
Platforms
- Mac
- Windows
- Linux
United States


Mend Renovate is a software product that helps developers automate dependency updates by identifying new package versions and delivering them to the application's codebase. It can generate pull requests and issues in the repository with details about the updates, including...
Yalc is an open-source monorepo tool that helps developers publish, install, and manage packages locally. It integrates smoothly with package managers like npm, yarn, and pnpm, allowing developers to work on multiple projects and packages simultaneously.


Aikido Security is a developer-first software security platform. We scan your source code & cloud to show you which vulnerabilities are actually important to solve. Triaging is sped up by massively reducing false-positives and making CVEs human-readable.




AWS CodeArtifact is a fully managed artifact repository service that aims to make it easy for organizations of any size to securely store, publish, and share software packages used in their software development process.

Create, host, and share packages with your team, and add artifacts to your CI/CD pipelines with a single click.


Use issues to collaborate on ideas, solve problems, and plan work. Share and discuss proposals with your team and with outside collaborators.


The next generation package manager for Kubernetes. Featuring a GUI and a CLI. Glasskube packages are dependency aware, GitOps ready and can get automatic updates via a central public package repository.





Composer is a package manager not in the same sense as Yum or Apt are. Yes, it deals with "packages" or libraries, but it manages them on a per-project basis, installing them in a directory (e.g. vendor) inside your project.

Keep your dependencies on GitHub up to date without the automatic creation of the Pull Requests to update the dependency and checking for the known vulnerabilities.
https://github.blog/2020-06-01-keep-all-your-packages-up-to-date-with-dependabot/

Depfu continuously updates your dependencies one at a time and creates a pull request with all the info you need. You stay in control.



FOSSA offers automated license scanning, dependency analysis and reports at each commit. Get a process up an running in 60 seconds, without slowing down development.
Bytesafe provides free, secure and hosted private registries along with the infrastructure needed to add security and control when consuming and sharing code, both with other teams and third parties.
Structure101 is an agile architecture development environment (ADE) that lets the software development team organize a codebase.




Dependency Update Automation for npm, composer and docker made easy. Check your git repositories for vulnerabilities now!.



Local CLI that scores dependency and runtime drift, checks known vulnerabilities, maps code relationships, and ranks upgrade work for CI.




Monitor and analyze Ruby project dependencies with a simple score, detailed reports, and no required access to your codebase.




A single pane of glass for understanding and mitigating risks across your entire codebase and supply chain.

Fusion is a PHP package manager that treats root projects and their dependencies as generic packages within a unified modular package system.
