Dependabot was acquired by GitHub! We're integrating it directly into the product (our first feature is automated security fixes) and it's our ideal outcome!
We tried our best to stay close to GitHub over the last 2 years - we knew that we were always in their "kill zone", so it was important for us to be acquired rather than killed if they ever decided to build automated dependency updates themselves. There was a lot of luck involved in achieving the outcome that we wanted, but it wasn't totally luck!
What is the reason for secrecy in so many deals like this? Do you have any general understanding of why this is you could share without going into specifics that could get you in trouble?
Yes! And the Dependabot brand is living on within GitHub - it's now the name of the GitHub-owned bot that creates automated security fixes for you, and will create dependency update PRs in general for you once we're fully integrated.
No, it feels great! We can have so much more impact with Dependabot within GitHub - lots of cool stuff planned. And not being responsible for all the accounting, legals and HR is such a relief!