# PSA: GitHub Dependabot now supports Julia

**URL:** <https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997>\
**Category:** Tooling\
**Tags:** announcement\
**Created:** [January 12, 2026, 5:38am UTC](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997 "2026-01-12T05:38:33Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![ianshmean](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ianshmean/32/216042_2.png) [@ianshmean](https://discourse.julialang.org/u/ianshmean)\
**Post date:** [January 12, 2026, 5:38am UTC](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/1 "2026-01-12T05:38:33Z")

</div>

GitHub’s [Dependabot](https://docs.github.com/en/code-security/getting-started/dependabot-quickstart-guide) now [supports Julia](https://github.blog/changelog/2025-12-16-dependabot-version-updates-now-support-julia/).

i.e. A standard `.github/dependabot.yml` file can now look like this to keep both github actions and julia deps up to date:

```yml
version: 2
updates:
  - package-ecosystem: "github-actions"
    directory: "/"
    schedule:
      interval: "weekly"
  - package-ecosystem: "julia"
    directory: "/"
    schedule:
      interval: "weekly"
    # groups: # uncomment to group all julia package updates into a single PR
    # all-julia-packages:
    # patterns:
    # - "*"

```

Dependabot has some benefits over CompatHelper:

- PRs will have their CI run automatically without manual interaction
- Any checked-in manifests will be updated, or if that fails the resolver errors will be shown directly in the PR body
- Workspaces are supported. Just set the `directory:` field like normal to the root where the main Project.toml is, and the sub-projects will be handled automatically. An example PR can be seen [here](https://github.com/IanButterworth/Julia-DependabotTest/pull/16)
- Dependabot can tie into security/CVE reporting

## Keeping `test/`, `docs/` etc. updated

If you have `test`, `docs` or other subdirectories setup with environments, it’s recommended to use the new `workspaces` feature (1.12+) to tie them together, which will work with the simple single `directory: "/"` configuration that the main example above gives. See the [[workspaces] docs](https://pkgdocs.julialang.org/v1/toml-files/#The-%5Bworkspace%5D-section) for more information on workspaces.

If you would rather not use workspaces, you can specify a list of directories, but note that the update for a single dependency will be opened in individual PRs, and thus may not fully test the change due to resolver conflicts between the environments. (workspaces make coordinating all that a lot easier).

> **Multi directory config example**
>
> ```yml
> version: 2
> updates:
> - package-ecosystem: "julia"
> directories: # Location of Julia projects
> - "/"
> - "/docs"
> - "/test"
> schedule:
> interval: "weekly"
> 
> ```

* * *

Current limitations

- Dependabot doesn’t yet support custom julia package registries, but there is work in progress to fix that.
- Dependabot runs on 1.12, so any manifest changes will be done from 1.12, irrespective of which version they were resolved with. Work is active in Pkg & juliaup to make it easier for the julia version of the manifest to be respected, which dependabot will then use.
- The CVE reporting side of dependabot requires a little more infrastructure on the github side [julia ecosystem support · Issue #1689 · github/advisory-database · GitHub](https://github.com/github/advisory-database/issues/1689)

Thanks to those who helped with the beta period that was announced [in November](https://discourse.julialang.org/t/this-month-in-julia-world-2025-10/133753)

Please feel free to suggest changes to this summary.

---

<div class="post-metadata">

**Author:** ![sylvaticus](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/sylvaticus/32/203883_2.png) [@sylvaticus](https://discourse.julialang.org/u/sylvaticus)\
**Post date:** [January 12, 2026, 7:58am UTC](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/2 "2026-01-12T07:58:56Z")

</div>

Just to be clear, from the Dependant doc you linked:

```julia-auto
Dependabot consists of three different features that help you manage your dependencies:

- Dependabot alerts: Inform you about vulnerabilities in the dependencies that you use in your repository.
- Dependabot security updates: Automatically raise pull requests to update the dependencies you use that have known security vulnerabilities.
- Dependabot version updates: Automatically raise pull requests to keep your dependencies up-to-date.

```

The function that is implemented for Julia, and that replace CompactHelper, is the 3rd one (up-to-date dependencies), right?

---

<div class="post-metadata">

**Author:** ![ianshmean](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ianshmean/32/216042_2.png) [@ianshmean](https://discourse.julialang.org/u/ianshmean)\
**Post date:** [January 12, 2026, 1:13pm UTC](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/3 "2026-01-12T13:13:47Z")

</div>

Correct. For the first two please +1 on this issue [julia ecosystem support · Issue #1689 · github/advisory-database · GitHub](https://github.com/github/advisory-database/issues/1689)

---

<div class="post-metadata">

**Author:** ![gdalle](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/gdalle/32/27854_2.png) [@gdalle](https://discourse.julialang.org/u/gdalle)\
**Post date:** [January 12, 2026, 1:18pm UTC](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/4 "2026-01-12T13:18:27Z")

</div>

Congrats on the hard work!  
Can I suggest showing how test and docs dependencies can be taken into account by dependabot? This may be the most important missing piece in the provided example.

---

<div class="post-metadata">

**Author:** ![giordano](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/giordano/32/2166_2.png) [@giordano](https://discourse.julialang.org/u/giordano)\
**Post date:** [January 12, 2026, 2:25pm UTC](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/5 "2026-01-12T14:25:59Z")

</div>

> [@gdalle](#):
>
> Can I suggest showing how test and docs dependencies can be taken into account by dependabot? This may be the most important missing piece in the provided example.

👇

> [@ianshmean](#):
>
> Workspaces are supported. Just set the `directory:` field like normal to the root where the main Project.toml is, and the sub-projects will be handled automatically. An example PR can be seen [here](https://github.com/IanButterworth/Julia-DependabotTest/pull/16)

---

<div class="post-metadata">

**Author:** ![gdalle](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/gdalle/32/27854_2.png) [@gdalle](https://discourse.julialang.org/u/gdalle)\
**Post date:** [January 12, 2026, 3:14pm UTC](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/6 "2026-01-12T15:14:51Z")

</div>

Sorry, I should have been clearer: I was referring to the following setup

```yml
    directories: # Location of Julia projects
      - "/"
      - "/docs"
      - "/test"

```

as being a worthy inclusion in the default example above instead of

```yml
    directory: "/"

```

---

<div class="post-metadata">

**Author:** ![giordano](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/giordano/32/2166_2.png) [@giordano](https://discourse.julialang.org/u/giordano)\
**Post date:** [January 12, 2026, 3:22pm UTC](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/7 "2026-01-12T15:22:00Z")

</div>

With a single directory _and_ the workspace you get a single PR, instead of 3 separate.

---

<div class="post-metadata">

**Author:** ![ianshmean](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ianshmean/32/216042_2.png) [@ianshmean](https://discourse.julialang.org/u/ianshmean)\
**Post date:** [January 12, 2026, 4:28pm UTC](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/8 "2026-01-12T16:28:34Z")

</div>

Thanks. I updated the OP to make that all clearer.

---

<div class="post-metadata">

**Author:** ![langestefan](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/langestefan/32/207923_2.png) [@langestefan](https://discourse.julialang.org/u/langestefan)\
**Post date:** [January 12, 2026, 5:52pm UTC](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/9 "2026-01-12T17:52:03Z")

</div>

> [@gdalle](#):
>
> Sorry, I should have been clearer: I was referring to the following setup
> 
> ```julia-auto
> directories: # Location of Julia projects
> - "/"
> - "/docs"
> - "/test"
> 
> ```
> 
> as being a worthy inclusion in the default example above instead of
> 
> ` directory: "/"`

So with below in mind, you probably don’t want to do this then?

> [@ianshmean](#):
>
> If you would rather not use workspaces, you can specify a list of directories, but note that the update for a single dependency will be opened in individual PRs, and thus may not fully test the change due to resolver conflicts between the environments. (workspaces make coordinating all that a lot easier).

---

<div class="post-metadata">

**Author:** ![ianshmean](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ianshmean/32/216042_2.png) [@ianshmean](https://discourse.julialang.org/u/ianshmean)\
**Post date:** [January 12, 2026, 6:44pm UTC](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/10 "2026-01-12T18:44:49Z")

</div>

From my perspective it does seem like the better way to handle multiple sub projects, but it’s a new feature so there might be some unknown issues

---

<div class="post-metadata">

**Author:** ![gdalle](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/gdalle/32/27854_2.png) [@gdalle](https://discourse.julialang.org/u/gdalle)\
**Post date:** [January 12, 2026, 7:39pm UTC](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/11 "2026-01-12T19:39:50Z")

</div>

My perspective was shaped by DifferentiationInterface.jl, where I absolutely cannot use workspaces unless I want to instantiate an environment containing every AD backend at once, including outdated ones which would severely restrict compatibility of other packages. More generally, workspaces are not ideal whenever there are subprojects with (a) wildly different or (b) very numerous dependencies.

---

<div class="post-metadata">

**Author:** ![fonsp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/fonsp/32/222349_2.png) [@fonsp](https://discourse.julialang.org/u/fonsp)\
**Post date:** [January 14, 2026, 12:06pm UTC](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/12 "2026-01-14T12:06:30Z")

</div>

Do you know where I can report bugs? E.g. this PR updated compat entries that were already included: [Bump the all-julia-packages group across 1 directory with 2 updates by dependabot[bot] · Pull Request #6 · JuliaPluto/BetterFileWatching.jl · GitHub](https://github.com/JuliaPluto/BetterFileWatching.jl/pull/6/changes)

---

<div class="post-metadata">

**Author:** ![ianshmean](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ianshmean/32/216042_2.png) [@ianshmean](https://discourse.julialang.org/u/ianshmean)\
**Post date:** [January 14, 2026, 12:51pm UTC](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/13 "2026-01-14T12:51:04Z")

</div>

> **[GitHub - dependabot/dependabot-core: 🤖 Dependabot's core logic for creating update PRs.](https://github.com/dependabot/dependabot-core)**
>
> 🤖 Dependabot's core logic for creating update PRs.

Start the issue with `julia: `

---

<div class="post-metadata">

**Author:** ![ianshmean](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ianshmean/32/216042_2.png) [@ianshmean](https://discourse.julialang.org/u/ianshmean)\
**Post date:** [January 16, 2026, 1:11pm UTC](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/14 "2026-01-16T13:11:49Z")

</div>

That should be fixed now. Thanks for the report (and review!)

---

<div class="post-metadata">

**Author:** ![JeffFessler](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/jefffessler/32/6650_2.png) [@JeffFessler](https://discourse.julialang.org/u/JeffFessler)\
**Post date:** [July 15, 2026, 8:15pm UTC](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/15 "2026-07-15T20:15:44Z")

</div>

How to configure it if I want dependabot to _only_ manage the root `Project.toml` and ignore the `docs/Project.toml` and `test/Project.toml`?  
I am getting tons of little PRs for docs/ and test/ and I don’t want to bother with compat for those subdirectories:  
[https://github.com/JuliaArrays/LazyGrids.jl/pulls](https://github.com/JuliaArrays/LazyGrids.jl/pulls)  
I asked copilot for help and it strongly suggested using `exclude-paths` which I tried but gave an dependabot error. And I tried to find documentation on the allowable syntax but all I could find was the general dependabot stuff, not the Julia-specific aspects.

---

<div class="post-metadata">

**Author:** ![Eben60](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/eben60/32/13475_2.png) [@Eben60](https://discourse.julialang.org/u/Eben60)\
**Post date:** [July 30, 2026, 10:34am UTC](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/16 "2026-07-30T10:34:30Z")

</div>

> [@JeffFessler](#):
>
> I asked copilot for help and it strongly suggested using `exclude-paths` which I tried but gave an dependabot error.

After trials, and dependabot `exclude-paths` errors, and discussions with AI, we found a possible solution - or rather a workaround - which is being tried right now. Here ist the [link to the article](https://ovirium.com/blog/exclude-directory-from-dependabot-checks/), and this is now in my `dependabot.toml`:

> **toml code**
>
> ```julia-auto
> updates:
> - package-ecosystem: "github-actions"
> directory: "/"
> schedule:
> interval: "weekly"
> groups:
> github-actions:
> patterns:
> - "*"
> 
> - package-ecosystem: "julia"
> directories:
> - "/"
> schedule:
> interval: "weekly"
> groups:
> all-julia-packages:
> patterns:
> - "*"
> 
> - package-ecosystem: "julia"
> directory: "/docs"
> schedule:
> interval: "monthly"
> ignore:
> - dependency-name: "*"
> 
> - package-ecosystem: "julia"
> directory: "/test"
> schedule:
> interval: "monthly"
> ignore:
> - dependency-name: "*"
> 
> ```

---

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [September 24, 2026, 5:02am UTC](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/17 "2026-09-24T05:02:40Z")

</div>

Dependabot recently updated a lot of my repositories with nonsensical compat bounds for standard libraries, as in

```julia-auto
LinearAlgebra = "< 0.0.1, 1"

```

then it notifies me that

```julia-auto
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

```

Then it keeps pestering me about these on a regular basis. Is this a recent bug? Can I do anything to avoid it?

---

<div class="post-metadata">

**Author:** ![ranocha](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ranocha/32/35588_2.png) [@ranocha](https://discourse.julialang.org/u/ranocha)\
**Post date:** [September 24, 2026, 5:24am UTC](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/18 "2026-09-24T05:24:59Z")

</div>

We got these for something like `test/Project.toml` and `docs/Project.toml` as well, but not for the main `Project.toml`. For us, it helped to set a Julia `[compat]` entry like `julia = "1.10"` in the other project files as well, mimicking what we had in the main `Project.toml`.

---

<div class="post-metadata">

**Author:** ![kellertuer](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/kellertuer/32/220707_2.png) [@kellertuer](https://discourse.julialang.org/u/kellertuer)\
**Post date:** [September 24, 2026, 6:41am UTC](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/19 "2026-09-24T06:41:34Z")

</div>

According to a discussion on Slack (Helpdesk, about 1.5 weeks ago) that might also have been a bug, and for the workspace case, the compat for Julia in the main Project file should be enough.

I am not able to read the following garbled LLM-PR [julia: derive stdlib floors for workspace and test environments from the Julia range Pkg resolves them under - Pull Request #16315 - dependabot/dependabot-core - GitHub](https://github.com/dependabot/dependabot-core/pull/16315)

but I think that should roughly even fix this in the future that just one lower bound on 1.10 should be enough in the main project file again.

---

<div class="post-metadata">

**Author:** ![TimG](https://avatars.discourse-cdn.com/v4/letter/t/82dd89/32.png) [@TimG](https://discourse.julialang.org/u/TimG)\
**Post date:** [September 24, 2026, 7:51am UTC](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/20 "2026-09-24T07:51:08Z")

</div>

Dependabot recently made a similar PR on my repo:

> Updates the requirements on Dates, Unicode, Random and Printf to permit the latest version.  
> Updates `Dates` to  
> Updates `Unicode` to  
> Updates `Random` to  
> Updates `Printf` to

Nothing is given as the `to` version in the PR text but:

```julia-auto
[compat]
  Colors = "0.12, 0.13"
+ Dates = "1.10"
  FileIO = "1"
  OrderedCollections = "1, 2.0"
  PrecompileTools = "1"
+ Printf = "1.10"
+ Random = "1.10"
  StyledStrings = "1.0.3"
  Tables = "1"
  UUIDs = "1.8"
+ Unicode = "1.10"
  XML = "0.4.6"
  ZipArchives = "2.5"
  julia = "1.10"

```

I already have the `julia = "1.10"` compat.

These compat entries seem harmless but unnecessary. Is there a particular reason for them?

[Next page](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997.md?page=2)
