01 / Access
Start with a narrow permission set
Bivouac works within the connected-repository scope and requests only:
- Repository metadata (read)
- Contents (read & write)
- Pull requests (write)
- Actions (read)
Stop spending engineering hours triaging dependency updates. Bivouac detects the issue, finds a compatible fix, and tests it against your codebase — so the PR that lands in your queue is already proven, not just proposed.
Connect GitHub, choose your policy, and let Bivouac prepare dependency updates for review. You approve and merge.

A guided first run
Start with one dependency change, one connected repository, and a policy your team can inspect. This is the real product setup: after you connect a repository, Bivouac opens and tests a reviewable patch PR, then waits for a human to approve and merge it.
Connected-repository setup: these permission and review stages apply after you start the product. The zero-permission example below is separate and does not connect to GitHub.
01 / Access
Bivouac works within the connected-repository scope and requests only:
02 / Actions
The permitted loop is deliberately easy to inspect:
03 / Escalation
The PR is blocked or left as a draft when there is:
This connected flow requests Repository metadata (read), Contents (read & write), Pull requests (write), and Actions (read). Merge execution is currently disabled: the first run opens a tested PR and waits for human approval. The zero-permission example below is separate and does not connect to GitHub. Read the full guardrails and human-review triggers before you connect a repository.
Full guardrailsWhat Bivouac does
One scannable row, not a feature blob. The agent’s three load-bearing jobs.
Detect
Govern
Patch
Illustrative audit evidence
This example uses a repeatable npm audit of the sample app's preserved baseline. It is not a captured Bivouac run, a live repository scan, or evidence that a pull request was created or tested.
npm audit · lodash@4.17.20
The preserved sample manifest and lockfile pin lodash 4.17.20.
The registry audit returned five lodash advisory records for this baseline version.
For this preserved sample lockfile, npm audit reports lodash 4.18.1 as the remediation target.
The audit describes the package version, advisory identifiers, and available remediation target. Bivouac's sample decision board is illustrative; this page does not request GitHub access, creates no PR, changes no repository, and does not run a live scan. A human remains responsible for approval and merge.
GHSA-35jh-r3h4-6jhm lists lodash 4.17.21 as patched for that advisory. A later lodash advisory, GHSA-r5fr-rjxr-66jc, affects versions through 4.17.23 and lists 4.18.0 and later as patched. For this fixture, npm audit selects lodash 4.18.1 as the current target. The GHSA threshold and fixture audit target describe different evidence.
Human in the loop
Bivouac doesn't replace your engineers — it removes the repetitive dependency work that doesn't require engineering judgment. The same loop runs on every signal: investigate, fix, test, review. Engineers stay responsible for approving and merging the calls that need humans.
If it doesn't require engineering judgment, Bivouac prepares it. If it does, Bivouac waits for you.
The four triggers below are the conditions that require extra human judgement. They are recorded in the policy pack and reviewable alongside the patch.
Cost of one vulnerability
A dependency alert still needs a compatible change and a review. Bivouac helps prepare that work while your team keeps the merge decision.
Human-led workflow
Investigate, update, test, review
Bivouac-assisted workflow
Prepare evidence and wait for approval
Your team keeps the merge decision
Human-led workflow
Investigate, update, test, review
Your team owns each step
Bivouac-assisted workflow
Prepare a change for review
Your team approves and merges
Built for teams that maintain their own stack
One product, four reasons to buy — pick the one that matches the room you're in.
CTO
Stop paying engineer-hours to maintain dependencies. Bivouac absorbs the maintenance tax so your roadmap keeps moving.
Engineering Manager
No more manually triaging Dependabot PRs at 8am. Bivouac sorts, tests, and opens the patch PR your team can merge.
Platform Team
Standardize dependency remediation across every repo. One policy, one agent, every service — without the bespoke plumbing per team.
Security Team
Turn every CVE alert into a tested, gated patch PR. Remediation lands before the alert ages out of the dashboard.
How Bivouac compares
Dependabot and Renovate keep raising PRs. Snyk keeps flagging advisories. Bivouac is the layer that decides what to do, proves it on your tests, and opens a reviewable PR — only paging a human when the call is genuinely contested.
| Capability | Bivouac | Dependabot | Renovate | Snyk Open Source |
|---|---|---|---|---|
| Monitors CVEs and breaking changes | watches CVEs and SemVer-major signals across public and private feeds | tracks public advisory feeds only | tracks public advisory feeds and SemVer drift | tracks public vulnerability feeds |
| Opens a patch PR | opens a draft PR against the right pin, fork, or downgrade | opens a forward-fix PR | opens a forward-fix or pin PR | no PR — surfaces an advisory |
| Runs your test suite | runs the project test suite before the PR is reviewable | not in scope | optional maintainer-configured merge after CI; the maintainer controls it | not in scope |
| Review and merge responsibility | Prepares a tested PR for review. Your team approves and merges it; Bivouac does not merge PRs. | maintainer reviews and merges | opt-in test-gate; maintainer merges | not in scope |
| Pages a human on judgment calls | pages the on-call only on contested decisions — license, public API, security surface | not in scope | not in scope | not in scope |
| Handles downgrades when a forward fix is not viable | picks downgrade-as-fix when the forward upgrade is incompatible | forward-only — fails open otherwise | forward-only by default | not a remediation tool |
Outcome-language summary — see pricing for what each plan actually runs in your repo.
See pricing →For the CTO and the auditor
Every bounded triage decision leaves a signed, exportable record — the same record your auditor wants to see. Compliance turns from a quarterly scramble into a query against the review log, and the agent reasons over your full dependency graph before it picks a remediation. Bivouac produces the evidence your team hands to the auditor — it isn't itself SOC 2 / NIS2 or EU CRA certified.
Incident handling and supply-chain security recorded per review — ready to inspect in the review log.
Vulnerability handling, supported-product disclosure, and signed SBOMs / software-bill-of-materials per build — exportable from the review log.
Append-only audit trail: which signal fired, which policy pack applied, which test gate made the PR ready for review.
Reads the full transitive dependency graph before picking forward-fix, downgrade, or pin — so the chosen remediation is the one your graph actually supports.
How it works
Every signal runs the same three-step track. The test suite is the gate. The on-call only gets paged for contested decisions, security-sensitive surfaces, license concerns, or failing builds.
Public and private advisory feeds, package-registry disclosures, and upstream breaking changes.
SemVer, peer usage, license posture, and security-sensitive surfaces — chosen locally before any code is touched.
The build is the gate. Red keeps the PR open. License churn, public-API breakage, and security-sensitive surfaces remain with a human — merge execution is disabled today.
Early access
Currently onboarding early-access teams.
Bivouac is in private beta with a small set of design partners. Each team gets a named engineer, a shared roadmap slot, and a private channel into the audit log — names will appear on this page once they've signed off, not before.
npm today, with more ecosystems coming
Hosted-product coverage is listed below; entries marked Coming soon are not yet supported. The public GitHub Action investigates npm dependency bumps in changed package.json files only; it does not handle PyPI, Maven, RubyGems, crates.io, or Go modules. The public GitHub Action does not merge pull requests.
Repos, advisories, PRs, review gates.
npm lockfiles, transitive SemVer, peer ranges.
pip, pyproject, private indexes · Coming soon
Maven, Gradle, OSV-scored advisories · Coming soon
go.mod graph, vendor trees, module proxy · Coming soon
Bundler, gemspec, RubyGems advisories · Coming soon
Cargo workspace graph, crates.io advisories · Coming soon
Composer, lockfile, private Packagist · Coming soon
NuGet, csproj, transitive resolve · Coming soon
Pricing
Free, Team, and Enterprise. The headline price is what the team actually pays — Free for your first repo, Team at $399/mo with 25 included repos, Enterprise on a custom quote. All tiers ship the same audit trail and the same test-gated review handoff.
Free
Team
Enterprise
Volume pricing for fleets and SOC 2 / NIS2 / CRA evidence-ready audit export on every tier. See full pricing →
Talk to us
Drop a few lines to talk with the Bivouac team — no SDR sequence, no demo gauntlet. We'll help you size the rollout and pick the right policy pack for the repos you actually watch.
Already running Dependabot, Renovate, or Snyk? Tell us what you're paying for them — we'll show you the overlap with what Bivouac earns.
Buyer-pipeline questions
Replacement posture, test-gate behavior, the approval layer, the upstream registry surface, and the self-hosted path — the pipeline questions, answered in plain language and laid out next to the 3-step “How it works” section above so the buyer can read them against the same flow.
Dependabot raises the PR and stops. Bivouac opens the PR, runs your tests, picks downgrade-as-fix when a forward upgrade is incompatible, and leaves a tested PR for human approval — so the team that was triaging Dependabot alerts gets a clearer handoff. Where Dependabot's coverage is what you want, leave it on; most teams run them in parallel for a quarter before turning the old one off.
The PR stays a draft and the merge is blocked — your test suite, run on a clean checkout, is the gate, not a courtesy. The failure is written to the audit row with the failing check name attached, so the regulator and your VP Eng can see what failed, not just that it failed. If the failure traces to a contested decision (license, public-API impact, security-sensitive surface) the on-call rotation is paged; if not, the signal stays open and we wait for you or for a follow-up run, runs, or both.
Yes — a required-reviewer rule in your policy pack keeps a human in the merge path after tests pass. Defaults are one reviewer for direct deps and two for transitive updates on a security-sensitive surface; the rule is written in the same diff as the patch so reviewers see it when they review the patch. Every review row records whether the rule fired, so the audit trail shows the approval context, not just that 'a human clicked Approve'.
Read the remediation + audit model →
npm today, via the public npm advisory data. PyPI, Maven Central, RubyGems, crates.io and Go are on the roadmap.
Yes — the same agent ships as a self-hosted runner your team deploys inside your own VPC, available on the Team and Enterprise tiers. It reads the same lockfile and CI surface, writes to the same audit-row format, and is billed the same per active repo — so the regulator and your auditor get an identical artifact whether the review came from our hosted agent or yours. Bring the runner to the data; the evidence format does not move.
Explore Bivouac
Skim the alternatives hub, the install guide, the integrations, the FAQ, the security posture, and the three switch-from plans for teams already running Renovate, Dependabot, or Snyk.
Light the watch
Connect GitHub → choose your policy → Bivouac finds an issue → opens the patch PR → runs your tests → prepares a reviewable PR → waits for a human to approve and merge. The test suite is the gate; the merge decision stays with your team.
No credit card. No sales call. No commitment.