Microsoft Corporation acquired Dependabot, a transaction announced in May 2019.
Dependabot operates in GitHub (GitHub sub-acquisition). Dependabot is an automated dependency-management tool that monitors a project's dependencies for known security vulnerabilities and opens pull requests to update them to safe versions. GitHub acquired and integrated it to power automated security updates for repositories, addressing the fact that most vulnerabilities remain unpatched long after disclosure.
Give GitHub built-in tooling to monitor dependencies for vulnerabilities and automate secure dependency upgrades.
Advisory firms were not disclosed for this transaction.