Skip to content
Dependency governance via pull request

Fix vulnerable dependencies before they reach production

Repohelm scans your dependency graph, ranks real exploitable risk, and opens the remediation pull requests for your team to review and merge.

repohelm[bot] opened PR #247
Bump lodash 4.17.20 → 4.17.21 (CVE-2021-23337)
CRITICAL HIGH FIXED
- "lodash": "4.17.20"
+ "lodash": "4.17.21"
// Fixes prototype pollution via mergeWith
3 repos 12 CVEs 47 PRs opened today
~4 min
first fix PR
94%
less PR noise
<0.3%
breakage rate

Trusted by platform and security teams at

~4 min
median time to first fix PR after scan
94%
reduction in false-positive PR noise with AI triage
200+
policy rules across 6 package ecosystems
<0.3%
unintended breakage rate on auto-merged PRs

Connect. Govern. Merge.

01

Connect your repositories

Authorize Repohelm via GitHub App or GitLab OAuth. No credentials stored, we use short-lived tokens scoped per repo.

02

Define your policy once

Set severity thresholds, allowed licenses, pinning rules, and blocked packages in a single YAML file, or start from a built-in template.

03

Watch the PRs arrive

Repohelm scans on push, on schedule, and on new CVE publication. Fix PRs are opened with root-cause context already written.

Built for platform teams governing dependencies across dozens of repositories

Multi-ecosystem scanning

npm, PyPI, Maven, Go modules, Cargo, RubyGems. One .repohelm.yaml governs them all, no per-ecosystem config duplication.

CVE triage with AI context

Scores each CVE against NVD, OSV, and GitHub Advisory Database, then re-ranks by actual reachability in your codebase. A CVSS 9.8 in a dev-only dep is not your highest priority.

Policy as code

Write governance rules in YAML or OPA/Rego. Check them into git. Your dependency policy lives in the same PR workflow as your application code.

Transitive dependency tracking

Full lockfile parsing surfaces risks buried 3 to 4 levels deep in your dependency graph. Most supply-chain compromises land in transitive deps, not direct ones.

License risk detection

Configurable allowlists for GPL, LGPL, AGPL, and SSPL. Flag copyleft licenses in production paths before they reach your legal team as a surprise.

SBOM export

Generate CycloneDX 1.5 or SPDX 2.3 SBOMs per repo or per org. Required for NTIA minimum elements compliance and increasingly requested by enterprise buyers.

Dependabot and Renovate open PRs. Repohelm governs dependencies.

Feature Dependabot Renovate Repohelm
AI CVE triage (reachability-aware)
Policy as code (OPA / YAML)
SBOM export
License risk detection
Multi-ecosystem in one config
Transitive lockfile analysis
Engineering governance reporting

From the teams using it

We had 80 open Dependabot PRs across 30 repos. Nobody was reviewing them because there was no context, just a version bump. Repohelm cut that to 11 actionable PRs in the first week, each one with a reachability summary already written.

Marcus Chen
Platform Engineering Lead, Veldthorn Logistics

We had a Confluence page listing our dependency rules that was three years out of date and nobody trusted. Moving to a .repohelm.yaml that lives in the repo and gets reviewed in PRs changed how our team actually engages with governance.

Priya Agarwal
Security Engineer, Corax Systems

Your dependency backlog will not clear itself. Repohelm will.

Free for up to 5 repositories. Full CVE triage, policy enforcement, and SBOM export included.