IT AI Index
Index Vendors › GitHub Dependabot · September 2026 Edition
GitHub · 1 category · Ranked

GitHub Dependabot

26Judge labels
3First choices
4Negative labels
8 of 12Models named it
1Category
September 2026 Edition. Every number here is derived from the raw labels under vendor table vv2026-09.2, every buyer segment counted.
Best standing
5% in SCA for small business buyers
Rank 7 of 49 in the mid-market standing
0 of 12 models made it the first choice on the direct prompt; 0% of its 7 labels there were negative.
By buyer segmentRead the same way at every buyer size.
In sca · each standing computed within its segment · bars are 0 to 100 · the accent bar is the product's own best reading

Standing by category

Every category where a model named GitHub Dependabot for a mid-market B2B company. Share is first choices across the direct, paraphrase, budget and scale prompts; rank is within every product named in that category.
CategoryFunctionShareRankNegative rateLabelsQuadrant
Software composition analysisDeveloper platform2%7 of 490%7under 10 labels · led by Trivy at 40%

Movement

This is the first edition on this tier, so no move can be computed for GitHub Dependabot yet. From the next edition this section shows, per buyer segment, whether its share moved by more than the measured noise floor.

By model

How each model treated GitHub Dependabot across every prompt where it was named for a mid-market B2B company. Twelve models, six prompts per category.
ModelFirst choiceAlternativeMentionNegativeLabels
Claude Haiku 4.500101
GPT-5.4 mini00000
Gemini 3.5 Flash11002
Perplexity Sonar00000
Grok 4.1 Fast01001
Mistral Small00000
DeepSeek V4 Flash01001
Llama 4 Maverick00000
Qwen 3.7 Flash00101
Kimi K200000
GLM 4.7 FlashX01001
MiniMax M2.500000

By framing

Which of the six questions produced the naming. By model says how often; this says asked what. The first-choice count on the right carries the marks of the models that produced it.
FramingLabels by classFirst choices
Direct6 labelsNone
Paraphrase4 labels1
Comparative4 labels2not counted in share
Budget-constrained5 labels2
Scale-constrained3 labelsNone
Negative4 labels1not counted in share
First choiceAlternativeMentionNegative26 labels in all, every segment counted; 3 of the 6 first choices count toward share, since the comparative and negative framings do not. The bar is one segment per label class, to scale within the framing.

What the models said for it

Verbatim evidence the judge attached to positive labels.

“If your budget is literally $0 and you use GitHub: Turn on Dependabot. It takes two minutes to configure” Gemini 3.5 Flash · SCA · budget prompt · first choice
“Use GitHub Dependabot (free, native) alongside Trivy for container/IaC.” GLM 4.7 FlashX · SCA · budget prompt · alternative
“GitHub Dependabot if you're on GitHub — it auto-opens fix PRs” DeepSeek V4 Flash · SCA · paraphrase prompt · alternative
“turn on Dependabot (which is free and built-in)” Gemini 3.5 Flash · SCA · paraphrase prompt · alternative

And against it

Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.

No model argued against it.

Named alongside

The products named in the same answers as GitHub Dependabot, over the 26 answers that named it. Took the first choice instead counts the answers where the other product was the first choice and GitHub Dependabot was named but was not.
ProductSame answerTook the first choice insteadHead to head
Snyk Open Source22 of 266Not in the top three
Trivy16 of 267Not in the top three
OWASP Dependency-Check14 of 260Not in the top three
Black Duck10 of 260Not in the top three
Mend.io10 of 260Not in the top three
Sonatype Lifecycle8 of 260Not in the top three
Aikido Security6 of 261Not in the top three
Endor Labs6 of 260Not in the top three
OSV-Scanner6 of 260Not in the top three
Semgrep Supply Chain5 of 261Not in the top three
A head-to-head page exists where both products are in a category's top three. The other rows are the same fact without a page behind them, so they link to the product instead.

What carried it into the answer

The sites and pages cited by the answers that named GitHub Dependabot. A fact about retrieval, not a lever on the model.

Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 15 of the 26 answers that named GitHub Dependabot and are not a share of its labels.

Domains cited

appsecsanta.com10
endorlabs.com10
dupple.com8
safeguard.sh8
aikido.dev7
guideflow.com7
mend.io7
ox.security7
cycode.com6
toolradar.com6

Seventy-six of the seventy-six domain citations in answers naming GitHub Dependabot came from somebody else's page.

Pages cited

Pages are listed as the models cited them.

Names read as GitHub Dependabot

What the judge wrote, as written, with how often. The vendor table decides that these count as GitHub Dependabot; a claim can dispute any of them.
Dependabot 3Dependabot (GitHub-native) 1
Is this your product?

Claim this page

Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when GitHub Dependabot's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as GitHub Dependabot, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.

It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at github.io is approved on the spot, any other address is reviewed by hand.

Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.

Subscribe to the pack