Dependabot started as a third-party tool, which GitHub acquired in May 2019. It uses data from the GitHub Advisory Database ...