Fix vulnerable dependencies before they reach production
Repohelm scans your dependency graph, ranks real exploitable risk, and opens the remediation pull requests for your team to review and merge.
Connect. Govern. Merge.
Connect your repositories
Authorize Repohelm via GitHub App or GitLab OAuth. No credentials stored, we use short-lived tokens scoped per repo.
Define your policy once
Set severity thresholds, allowed licenses, pinning rules, and blocked packages in a single YAML file, or start from a built-in template.
Watch the PRs arrive
Repohelm scans on push, on schedule, and on new CVE publication. Fix PRs are opened with root-cause context already written.
Built for platform teams governing dependencies across dozens of repositories
Multi-ecosystem scanning
npm, PyPI, Maven, Go modules, Cargo, RubyGems. One .repohelm.yaml governs them all, no per-ecosystem config duplication.
CVE triage with AI context
Scores each CVE against NVD, OSV, and GitHub Advisory Database, then re-ranks by actual reachability in your codebase. A CVSS 9.8 in a dev-only dep is not your highest priority.
Policy as code
Write governance rules in YAML or OPA/Rego. Check them into git. Your dependency policy lives in the same PR workflow as your application code.
Transitive dependency tracking
Full lockfile parsing surfaces risks buried 3 to 4 levels deep in your dependency graph. Most supply-chain compromises land in transitive deps, not direct ones.
License risk detection
Configurable allowlists for GPL, LGPL, AGPL, and SSPL. Flag copyleft licenses in production paths before they reach your legal team as a surprise.
SBOM export
Generate CycloneDX 1.5 or SPDX 2.3 SBOMs per repo or per org. Required for NTIA minimum elements compliance and increasingly requested by enterprise buyers.
Dependabot and Renovate open PRs. Repohelm governs dependencies.
| Feature | Dependabot | Renovate | Repohelm |
|---|---|---|---|
| AI CVE triage (reachability-aware) | |||
| Policy as code (OPA / YAML) | |||
| SBOM export | |||
| License risk detection | |||
| Multi-ecosystem in one config | |||
| Transitive lockfile analysis | |||
| Engineering governance reporting |
From the teams using it
We had 80 open Dependabot PRs across 30 repos. Nobody was reviewing them because there was no context, just a version bump. Repohelm cut that to 11 actionable PRs in the first week, each one with a reachability summary already written.
We had a Confluence page listing our dependency rules that was three years out of date and nobody trusted. Moving to a .repohelm.yaml that lives in the repo and gets reviewed in PRs changed how our team actually engages with governance.
Your dependency backlog will not clear itself. Repohelm will.
Free for up to 5 repositories. Full CVE triage, policy enforcement, and SBOM export included.