/already-using-dependabot
Persona · Dependabot teams

Already using Dependabot? Bivouac layers on top — your PR queue drains, the backlog clears.

If you're already running Dependabot, you're tired of the PR backlog — the Friday triage, the green-PR pile-up, the reopen-on-flake rotation. Dependabot does the easy half: it opens the patch PR and bumps the lockfile. The other half — the review queue, the merge button, the on-call rotation that decides between forward fix and downgrade, the bot that pages itself before the alert ages out — still sits on a human's plate. Bivouac layers Investigate → Fix → Test → Review on top of the same PR stream Dependabot already opens, so the queue arrives with green-test evidence instead of accumulating on the reviewer.

  1. 01Investigate
  2. 02Fix
  3. 03Test
  4. 04Review
Start freeDependabot keeps running. Bivouac sits on top — same PRs, smaller queue.
Dependabot config retiredHuman approval after green testsSee the full /vs/dependabot comparison →

The four-stop flow

What Bivouac adds on top of the PR Dependabot already opens.

Dependabot does the easy half — the PR, the lockfile bump, the branch. Bivouac picks up the queue-management half, the four stops a Dependabot-only patch PR still needs to clear before it shows up on main.

  1. 01Investigate

    Dependabot opens the PR; Bivouac reads the lockfile diff, the SemVer-major upstream change, and the advisory source behind each bump so the decision between forward fix, downgrade, and pin is solved locally — not left to whoever opens the PR first.

  2. 02Fix

    Dependabot ships a locked lockfile patch; Bivouac selects forward fix, downgrade, or pin from the repo's policy pack, so the version chosen for each surface (monorepo, microservice, lockfile-strict) is the one your policy picked — not the one Dependabot set first.

  3. 03Test

    The PR is reviewable only after the repo’s own test suite runs on CI. Bivouac’s policy pack gates the "ready for review" state on a green build — a human retains the merge button after the evidence is ready.

  4. 04Review

    On green tests, Bivouac leaves a reviewable PR and waits for approval. The on-call is paged only on the contested outcomes — license changes, public-API breaks, security-sensitive surfaces — and every row carries feed source, decision rationale, test output, and review outcome.

Same Dependabot config, retired.Bivouac reads the PR stream Dependabot produces; the dependency-manager config you already wrote — schedule, grouping, manifest pinning — goes away, replaced by bivouac-action pointed at the same repo.

The headline difference

Same Dependabot coverage. Smaller queue by end of week.

The deep comparison lives on /vs/dependabot. The short version is below — one sentence, every word drawn from the same source as the comparison page.

Bivouac vs Dependabot

Bivouc opens downgrade PRs vs Dependabot's weekly PR sprawl — same CVE coverage, but the decision between forward fix and pin is solved locally and the green-tested PR is ready for approval.
Try it on one repo first. The same Dependabot coverage, a smaller queue for the on-call, and downgrade decisions that don't wait on review.

Caveat — Useful — but the human still owns the decision tree.Verbatim from the “How Bivouc compares” research on the landing page.

Read next

Three field reports for teams already running Dependabot.

Benchmark numbers, picking framework, and the Snyk comparison — three posts that teed up the layering story this page tells.

Retire the config. Keep the coverage.

One repo, same Dependabot, smaller queue by end of week.

Drop the Dependabot config. Install bivouac-action. Point it at the same repo. Watch each PR arrive tested and reviewable, with pages only on the contested outcomes. Free for the first repo. No card to start.

Start freeDependabot keeps running. Bivouac sits on top — same PRs, smaller queue.
Read the bivouac-action quickstart

Free for the first repo. No card to start. See /pricing for the per-repo breakdown →