Your first patch PR in 10 minutes.
An on-call agent for dependency updates. It opens, tests, and merges dependency security PRs in your GitHub repos — connect GitHub, choose your policy, and your first patch PR is usually live in 10 minutes.
- 01Connect GitHub
- 02Choose your policy
- 03Bivouac finds an issue
- 04Patch PR
- 05Tests
- 06Merge
Live walkthrough
Watch a CVE go from disclosure to merged PR.
Here is one captured run — 6 minutes, 5 stages, no engineer woken up. The same track runs on every signal we pick up.
bivouac · run · lodash/cve-2020-28500
- 09:421/6
CVE detected
lodash < 4.17.21 (CVE-2020-28500 in lodash.template prototype pollution)
- 09:432/6
Impact assessed
Affected dependency found in 3 repositories (catalog-graph walk)
- 09:443/6
Fix selected
Upgrade compatible with current dependency graph (4.17.21 → no peer churn)
- 09:454/6
PR created
fix: upgrade lodash to 4.17.21 (draft, awaiting tests)
- 09:475/6
Tests passed
1,248 tests passed · 12 repos in poly-repo · 0 churn
- 09:476/6
PR merged
Security issue resolved without waking an engineer
Real captured run · 09:42 → 09:47 · 0 engineer pages
Human in the loop
AI handles the routine. Engineers handle the exceptions.
Bivouac doesn't replace your engineers — it removes the repetitive dependency work that doesn't require engineering judgment. The same loop runs on every signal: investigate, fix, test, merge. Engineers stay responsible for the calls that need humans.
If it doesn't require engineering judgment, Bivouac closes it. If it does, Bivouac pages you.
The four triggers below are the only conditions that wake the on-call. This is an opt-in rule per repo and lives inside the policy pack, so it's reviewable in the same diff as the patch.
Cost of one vulnerability
What does one vulnerability actually cost your team?
Same CVE. Same fix. Same end state. The gap between these two timelines is why teams buy Bivouac — not because the alert is unique, but because the path from alert to merge is.
Without Bivouac
4–6 hours
10 manual steps · engineer on the loop
With Bivouac
5–15 minutes
5 automated steps · engineer asleep
Without Bivouac
4–6 hours
10 manual steps
- CVE detected
- engineer receives alert
- investigates
- finds compatible version
- creates PR
- CI runs
- tests fail
- engineer investigates
- fixes dependency conflict
- PR reviewed → merged
With Bivouac
5–15 minutes
5 automated steps
- CVE detected
- Bivouac investigates
- creates fix
- runs tests
- merges if green
Median across the Bivouac benchmark suite, 2026-Q2 — same CVE, same test suite, real engineer time measured end-to-end.
Built for teams that maintain their own stack
Who Bivouac is for
One product, four reasons to buy — pick the one that matches the room you're in.
CTO
Stop paying engineer-hours to maintain dependencies. Bivouac absorbs the maintenance tax so your roadmap keeps moving.
Engineering Manager
No more manually triaging Dependabot PRs at 8am. Bivouac sorts, tests, and opens the patch PR your team can merge.
Platform Team
Standardize dependency remediation across every repo. One policy, one agent, every service — without the bespoke plumbing per team.
Security Team
Turn every CVE alert into a tested, gated patch PR. Remediation lands before the alert ages out of the dashboard.
How Bivouac compares
More than alerts — Bivouac closes the loop.
Dependabot and Renovate keep raising PRs. Snyk keeps flagging advisories. Bivouac is the layer that decides what to do, proves it on your tests, and ships it — only paging a human when the call is genuinely contested.
| Capability | Bivouac | Dependabot | Renovate | Snyk Open Source |
|---|---|---|---|---|
| Monitors CVEs and breaking changes | watches CVEs and SemVer-major signals across public and private feeds | tracks public advisory feeds only | tracks public advisory feeds and SemVer drift | tracks public vulnerability feeds |
| Opens a patch PR | opens a draft PR against the right pin, fork, or downgrade | opens a forward-fix PR | opens a forward-fix or pin PR | no PR — surfaces an advisory |
| Runs your test suite | runs the project test suite before the PR is reviewable | not in scope | opt-in — automerge requires explicit maintainer config | not in scope |
| Merges when green | auto-merges on green with a signed audit row | no merge authority | merges only when CI passes AND maintainer config allows | not in scope |
| Pages a human on judgment calls | pages the on-call only on contested decisions — license, public API, security surface | not in scope | not in scope | not in scope |
| Handles downgrades when a forward fix is not viable | picks downgrade-as-fix when the forward upgrade is incompatible | forward-only — fails open otherwise | forward-only by default | not a remediation tool |
Outcome-language summary — see pricing for what each plan actually runs in your repo.
See pricing →For the CTO and the auditor
NIS2, CRA, SOC 2, and the dependency graph — generated as a side effect of the merge.
Every autonomous decision leaves a signed, exportable record — the same record your auditor wants to see. Compliance turns from a quarterly scramble into a query against the merge log, and the agent reasons over your full dependency graph before it picks a remediation. Bivouac produces the evidence your team hands to the auditor — it isn't itself SOC 2 / NIS2 or EU CRA certified.
24/7 incident handling and supply-chain security recorded per merge — no end-of-quarter scramble.
Vulnerability handling, supported-product disclosure, and signed SBOMs / software-bill-of-materials per build — exportable from the merge log.
Append-only audit trail: which signal fired, which policy pack applied, which test gate cleared the merge.
Reads the full transitive dependency graph before picking forward-fix, downgrade, or pin — so the chosen remediation is the one your graph actually supports.
Buyer FAQ
Five questions a buyer should be able to answer in under thirty seconds.
Plain-language answers, the way we wish someone had given them to us. Skim the questions; the answer you’re looking for is almost certainly in there. If something’s missing, ping us — we read every message.
How it works
From disclosure to merged fix — on its own shift.
Every signal runs the same three-step track. The test suite is the gate. The on-call only gets paged for contested decisions, security-sensitive surfaces, license concerns, or failing builds.
- 01WatchesContinuous watch on your GitHub repositories and dependency trees.
Public and private advisory feeds, package-registry disclosures, and upstream breaking changes — scanned every five minutes.
- 02InvestigatesReads the signal. Picks forward fix, downgrade, or pin against your policy pack.
SemVer, peer usage, license posture, and security-sensitive surfaces — chosen locally before any code is touched.
- 03Patch, test, mergeOpens a draft PR, runs the project test suite, and auto-merges on green.
The build is the gate. Red blocks the merge. License churn, public-API breakage, and security-sensitive surfaces stop at a human — every widening is opt-in per repo.
Dimension by dimension
How Bivouac compares.
Four dimensions where the bots disagree on what counts as a fix. Bivouac’s column reflects only what runs in your repo today — anything we can’t ship on a green build, we won’t claim here.
| Dimension | Bivouac | Dependabot | Renovate | Snyk Open Source |
|---|---|---|---|---|
| Detection surface | Partial | |||
| Remediation speed | Partial | Partial | No | |
| Test-suite enforcement | No | Partial | No | |
| Human escalation rules | No | No | No |
Each cell is grounded in what each plan runs and the comparison blog series.
See the deep comparisons →How Bivouac works
From disclosure to merged fix — on its own shift.
What happens between signal and shipped fix: four ordered steps the agent runs against every connected repo, no shortcuts, no skipped gates.
- 01DetectA CVE drops or an upstream ships a breaking change — we read it from your repo’s dependency tree, not a public feed.
- 02InvestigateTrace the impact in your lockfile, your test suite, and your call sites. Pick the smallest viable fix path before any code is touched.
- 03Patch and testOpen a draft PR, run the project’s test suite, and pick a downgrade when a forward fix isn’t viable. The build is the gate.
- 04Merge or pageMerge on green. Page a human on contested license churn, security-sensitive surfaces, public-API breakage, or red builds.
How Bivouac compares
Capability by capability — and where to read more.
Six properties that decide whether a dependency-watch tool actually closes the loop. Each competitor’s column links to the published comparison post so you can read the full argument behind every cell.
| Capability | Bivouac | Dependabot | Renovate | Snyk Open Source |
|---|---|---|---|---|
| Autonomous patch PR | opens a draft PR against the right pin, fork, or downgrade | opens a forward-fix PR | opens a forward-fix or pin PR | no PR — surfaces an advisory |
| Breaking-change detection on dep bumps | lockfile drift and SemVer-major upstream moves are a trigger | not a trigger — advisory-driven | tracks SemVer-major upstream moves | not a trigger — advisory-driven |
| Fallback downgrade | picks downgrade-as-fix when the forward upgrade is incompatible | forward-only — fails open otherwise | forward-only by default | not a remediation tool |
| Human-page-on-judgment calls | pages the on-call only on contested decisions — license, public API, security surface | not in scope | not in scope | not in scope |
| Audit log / attestation | every merged patch carries a signed audit row (feed, decision, test outcome) | not in scope | not in scope | not in scope |
| Transitive CVE coverage | NVD + GHSA, scoped to direct and transitive per repo policy | public advisory feeds, direct-dependency scope | public advisory feeds, transitive scope | NVD + vendor-curated DB, direct + transitive scope |
Each competitor column links to the in-depth comparison post — Bivouac vs Dependabot, Bivouac vs Renovate, and Bivouac vs Snyk Open Source.
Early access
Built for teams that can't afford dependency drift.
Currently onboarding early-access teams.
Bivouac is in private beta with a small set of design partners. Each team gets a named engineer, a shared roadmap slot, and a private channel into the audit log — names will appear on this page once they've signed off, not before.
Ecosystem coverage
One agent across every runtime your stack touches.
Repos, advisories, PRs, merge guardrails.
npm lockfiles, transitive SemVer, peer ranges.
pip, pyproject, private indexes.
Maven, Gradle, OSV-scored advisories.
go.mod graph, vendor trees, module proxy.
Bundler, gemspec, RubyGems advisories.
Cargo workspace graph, crates.io advisories.
Composer, lockfile, private Packagist.
NuGet, csproj, transitive resolve.
Early-access teams
Pricing
Per active repository. No tier zoo.
Three plans, billed monthly per active repo. All tiers ship the same audit trail and the same test-gated merge guardrails — higher plans widen what the agent handles autonomously and how fast.
Free
Starter
Team
Enterprise
Volume pricing for fleets and SOC 2 / NIS2 / CRA evidence-ready audit export on every tier. See full pricing →
Talk to us
Got a fleet, a regulated environment, or a tricky policy?
Drop a few lines and someone from the Bivouac team will respond within one business day — no SDR sequence, no demo gauntlet. We'll help you size the rollout and pick the right policy pack for the repos you actually watch.
Already running Dependabot, Renovate, or Snyk? Tell us what you're paying for them — we'll show you the overlap with what Bivouac earns.
Buyer objections, answered
Five questions a buyer should be able to answer.
Pricing, test gates, what we read, the upstream registry set, and how the on-call page actually fires — the answers in plain language, the way we wish someone had given them to us.
Light the watch
Your first patch PR in 10 minutes.
Connect GitHub → choose your policy → Bivouac finds an issue → opens the patch PR → runs your tests → merges on green. The test suite is the gate; humans stay on the bench.
No credit card. No sales call. No commitment.