Skip to content

Your dependencies, maintained.

StackRadar upgrades your dependencies, passes your own CI, and merges under policies you set. Your team stays on product work.

30 days free. Observe mode merges nothing.

Trusted by engineering teams at

  • Image
  • Estoty
  • FinoTech

Scanners find everything. Nobody fixes anything.

Dependabot opens PRs. Snyk mails a digest. The upgrade plan rots in a doc. And agents add hundreds of packages nobody reviewed. Every kind of dependency debt ends at a list, and every list waits for a sprint nobody has.

Product work wins the priority fight, and it should. The fix is not another report. The fix is removing the work.

Bump undici from 6.21.0 to 7.3.1

#482 · dependabot[bot] · opened 5 months ago

build failing

Bump laravel/framework from 12.40.0 to 13.0.2

#517 · dependabot[bot] · opened 3 months ago

2 checks failing

Bump shell-quote from 1.8.3 to 1.8.4

#601 · dependabot[bot] · opened 3 weeks ago

Review required

Bots merge what passes untouched. StackRadar fixes what doesn’t.

The long versions: StackRadar vs Renovate · StackRadar vs Dependabot

Your bots

Bump undici from 6.21.0 to 7.3.1

#482 · dependabot[bot] · opened 5 months ago

build failingwaiting on someone
Automated updates land what passes untouched. The PRs that rot need code: a renamed API, a breaking major.

StackRadar

undici 6.21.0 → 7.3.1, call sites updated

#689 · stackradar[bot] · references #482

checks runningall checks passingMerged
Agents make that change, pass your CI, and merge under your policy. Your bots stay. Their PRs become input.

What happens to the pile

Three jobs, one owner. Dependencies only, not another AppSec platform.

Merge the lists

Every tool, one owner.

The same issue from four tools becomes one item with one fix. Vulnerabilities, EOL dates, licenses, stale majors: one ranked dataset.

Cut the noise

Fewer things asking for you.

Withdrawn advisories close on sight. So do findings that miss the version you run, each with a reason you can read and reverse. Nothing closes in silence.

Your tools find. StackRadar finishes.

Bring your scanners or use ours

Every source feeds one radar. No scanners? StackRadar scans on its own. Runs on GitHub; GitLab and Bitbucket are planned.

Same finding, three reporters

DependabotalertCVE-2026-24391 · shell-quote 1.8.3
SnykfindingCVE-2026-24391 · shell-quote 1.8.3
TrivyCI reportCVE-2026-24391 · shell-quote 1.8.3
CCVE-2026-24391shell-quote 1.8.3→ 1.8.4Queued

One item, one owner. The reporters stay on it as provenance.

Every kind of debt, one queue

Vulnerabilities are one lane. EOL dates, abandoned packages, license conflicts, and stale majors land in the same queue, ranked by the same rules.

FindingFixStatus
EOLSR-1055vue 2.7.16 · past end of lifemigrationNeeds you
ABDSR-1049moment 2.30.1 · unmaintainedmigrationNeeds you
LICSR-1046mariadb 3.3.0 · LGPL-2.1reviewQueued
UPDSR-1060vite 5.4.11 · 2 majors behind→ 7.1.0Queued
HCVE-2021-44906minimist 1.2.5 · via mkdirp→ mkdirp 0.5.6Fixing
CCVE-2026-24391shell-quote 1.8.3→ 1.8.4Merged

You set the rules once

Policies decide what merges on its own and what waits for a yes. Start narrow, widen when the paper trail earns it.

Merge policyapi-service

Auto-merge patch and minorwhen CI is green
Soak window24 hours green before merge
Majorsask first
EOL horizonflag 90 days out
License policyno copyleft in prod
Test editsflagged in every diff
Never touchpayments/**
postcss 8.4.29 → 8.4.31patchMerged, CI green
laravel/framework 13majorWaiting for your yes

Proof, not homework

The digest reads like a changelog, not an alarm. What merged, what closed and why, and the one thing that needs your yes.

# devWeekly digest · Mon 09:00

StackRadarAPP9:00 AM

Maintenance digest for ridgeline

Merged: 11 upgrades across 6 repos

Closed as noise: 2, withdrawn upstream

EOL: vue 2 past end of life. Migration plan drafted.

Needs you: laravel/framework 13, breaking API in code you own. One question attached.

Observe mode builds your backlog without merging a thing.

Safe to let go

Autonomy is a dial, not a switch. Every notch leaves a trail.

Observe mode first
Connect it and it merges nothing. It shows every action it would take until you flip auto-merge on.
Nothing merges red
Every change passes your own CI first. Test edits are flagged and block auto-merge by default, and agents never rerun flaky checks to reach green.
Inside branch protection
Your rules stay on. Where reviews gate the merge, you grant the bypass yourself, scoped per repo. Policy lives in your repo as a committed file, so turning the dial takes a reviewed PR.
Every merge keeps its trail
Finding, diff, checks: the record stays attached. One click opens the revert PR.
One ask when it matters
A breaking major in code you own becomes one question with context, not a list.
Your code stays yours
Agents index the repo to find call sites and edit only the paths a fix touches, in a per-run sandbox. The index dies with the sandbox, and nothing trains on your code.

Observe mode is the default. When the queue earns your trust, a walkthrough hands you the dial.

An agent can fix it. It can’t own it.

An agent starts from zero every run. No state: what’s open or reverted. No topology: which repos ship it. No policy: what may merge where. StackRadar holds all three and puts agents to work inside them.

The clock changed too. AI tooling adds dependencies faster than anyone reviews them, and from September 2026 the EU’s Cyber Resilience Act puts a legal clock on reporting exploited vulnerabilities in products sold in the EU. The pile grows on a schedule now. Clearing it has one too.

Start free trial

Fixes your stack

JavaScript & TypeScript

npm · pnpm · Yarn · Deno

PHP

Composer

Python

pip · Poetry · Pipenv · uv

PlannedGoRustJavaRuby.NETDockerTerraformGitHub ActionsTell us what you run

Pricing

Start with the picture. Add control. Hand over the keys when you’re ready.

Per team, not per seat. Unlimited members on every plan.

Track

€20/month

For a handful of projects.

  • Vulnerability tracking across every repo
  • One ranked backlog for the team
  • Push lockfiles from CI, no repo access needed
  • Slack, Discord, and email digests
  • Unlimited team members
  • 10 projects included, then €1 per project
Start free trial

Resolve

From €500/month

For teams that want it handled.

  • Everything in Control
  • Agents fix and merge under your policy
  • Soak windows and one-click revert
  • Priced by project count
Book a walkthrough

Enterprise

Custom

For orgs with their own rules.

  • Agents run in your own cloud
  • SSO, SCIM, and audit export
  • Model calls under your own LLM agreement
  • 24/7 response when a merge goes wrong
  • A named engineer who knows your repos
  • Custom contracts and volume pricing
Book a walkthrough

Pricing is per team, per month. Track and Control start with a 30-day free trial. Resolve is early access: a walkthrough first, 30 minutes, no access to your code. Early partners lock their rate.

What a bill looks like at your project count

Questions before you let go

Short answers, no hedging.

Comparing the update bots? Renovate vs Dependabot

Something missing? Ask us

Can’t I point my own coding agent at the PR pile?

Plenty of teams do, and it works: an agent plus a sharp engineer clears the pile. What it does not do is stay cleared. The agent starts from zero every run: it does not know what is open, what is soaking, what got reverted, which repos ship the package, or what your policies allow. StackRadar holds that state and topology and runs the loop on its own, so the pile stays cleared without the sharp engineer.

What if an upgrade breaks production?

Green CI is necessary, not sufficient. Soak holds a green change short of the merge for the window you set; a failed rerun or a new advisory resets the clock. If something still slips through, one click opens the revert PR and the trail shows what merged, when, and why.

How is this different from Renovate or Dependabot?

Renovate automerges patch bumps when CI is green. Keep it: its PRs become input. The backlog rots where automerge stops: majors, breaking changes, the same CVE from four tools. StackRadar’s agents do that work, and big migrations land as small, sequenced PRs.

Is StackRadar a security tool?

Security is one lane. StackRadar is a dependency management platform: the vulnerability backlog sits beside EOL dates, abandoned packages, license conflicts, and versions that fall behind. One queue, one owner, every kind of dependency debt.

Does StackRadar help with the EU Cyber Resilience Act?

StackRadar is not a compliance platform: no SBOMs, no ENISA filings, no audit binders. Keep the tools that do that work. The CRA also demands what paperwork cannot deliver: security updates shipped for the product’s whole support period, and a fix that lands fast when a vulnerability turns exploited. That fix-and-merge labor is StackRadar’s job. Reporting duties start in September 2026; most other obligations apply from December 2027.

We already pay for Snyk and GitHub Advanced Security. What changes?

Keep them or drop them; both work. Their findings become input, deduped into one queue, so nobody pays attention twice. StackRadar also scans on its own, so a scanner seat you keep is a choice, not a requirement. And pricing is per team, not per seat.

How do I justify this to a CFO cutting spend?

Two lines. Spend: per-team pricing does not grow with headcount, and if StackRadar’s own scan covers you, a per-seat scanner bill can go. Hours: the upgrade work your engineers stop doing. Run the trial and count both.

What access does StackRadar need?

A GitHub App with per-repo grants: read code, write branches and pull requests. It merges only when your required checks pass. Where reviews gate the merge, you add StackRadar to your ruleset’s bypass list yourself: one reviewed settings change, visible in the audit log, revocable any time. Uninstalling the App ends access on GitHub’s side.

Where does my code go?

Agents read the paths a fix touches, in a per-run sandbox. Model calls run under a zero-retention agreement; subprocessors are in the DPA. Hard questions: security@stackradar.com.

Which ecosystems does it fix?

npm (with pnpm, Yarn, and Deno lockfiles), Composer, and Python (pip, Poetry, Pipenv, uv). Go, Rust, Java, Ruby, and .NET are planned.

What does early access look like?

Track and Control are self-serve: sign up, connect in observe mode, and the backlog fills. The first 30 days are free. Resolve starts with a walkthrough, where we tune policies with you before anything merges. Early partners lock their rate.

Consider it merged.

Start on Track and watch the backlog dedupe itself. The dial starts with a walkthrough.

30 days free on Track and Control.