Tool comparison guide
npm audit vs Snyk vs Dependabot: which tool to use for your project
Three tools, different databases, different integration points, and overlapping (but not identical) vulnerability coverage. This comparison explains exactly what each catches, what it misses, and which combination makes sense for your workflow.
Quick comparison
| Feature | npm audit | Dependabot | Snyk |
|---|---|---|---|
| Vulnerability database | npm Advisory DB | GitHub Advisory DB | Snyk DB (superset) |
| CVE coverage | Partial | Partial | Broadest |
| Automated fix PRs | No | Yes (GitHub) | Yes (GitHub+) |
| Works without GitHub | Yes (CLI) | No | Yes (CLI/web) |
| License scanning | No | No | Paid tier |
| Typosquatting detection | No | No | No |
| Abandoned package signals | No | No | No |
| Cost | Free (built-in) | Free (GitHub) | Free tier + Paid |
| Setup required | None — part of npm | Enable in repo settings | CLI install or GitHub app |
npm audit
npm audit is built into npm (available since npm 6). It compares the packages in your package-lock.json or yarn.lock against the npm Advisory Database — a registry of CVEs that have been disclosed to npm, Inc.
# Run a full audit
npm audit
# Exit non-zero only on high and critical findings (useful in CI)
npm audit --audit-level=high
# Automatically apply safe fixes
npm audit fix
# Apply fixes that include semver-major upgrades (use with caution)
npm audit fix --force
What npm audit does well
It requires zero setup — if you have npm, you have npm audit. It is fast (milliseconds for most projects), easy to add to a package.json script or a CI step, and the output is machine-readable with --json. For well-known, widely-used packages, its CVE coverage is reliable.
Where npm audit falls short
The npm advisory database is reactive: it depends on maintainers and the community submitting reports. Newly discovered CVEs can take days to weeks to appear. For less popular packages, coverage is thin. npm audit also has no knowledge of license risk, package abandonment, or whether a package name looks like a typosquatting attempt.
npm audit will not flag it — because the package name itself is unknown to the advisory database. Supply-chain attacks via name confusion are outside its detection scope entirely.
Dependabot
Dependabot is a GitHub-native feature (acquired by GitHub in 2019) that opens automated pull requests to update dependencies. It has two modes relevant to security:
- Security alerts — GitHub detects a known vulnerability in your dependency tree and notifies you (no PR, just an alert).
- Security updates — Dependabot automatically opens a PR with the minimum version bump to fix the vulnerability.
Dependabot uses the GitHub Advisory Database, which aggregates CVEs from NVD, the npm Advisory DB, GHSA (GitHub Security Advisories), and other sources. Its coverage is broader than npm audit alone but narrower than Snyk.
Enabling Dependabot
Go to your repository’s Security tab → Dependabot → enable both alerts and security updates. No CLI installation, no configuration file required for the basic setup.
For more control, add a .github/dependabot.yml file:
version: 2
updates:
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"
# Only open PRs for security patches, not version bumps
open-pull-requests-limit: 10
Dependabot’s key advantage
The automated PR workflow means you do not have to check a dashboard — the fix arrives as a pull request with the diff, the vulnerability description, and a link to the advisory. For teams already on GitHub, this is the lowest-friction way to stay current on security patches.
Snyk
Snyk maintains its own vulnerability database — a dedicated security research team curates findings from NVD, the GitHub Advisory Database, npm’s advisory DB, and independent research. The result is a database that is a superset of what npm audit and Dependabot see: Snyk often publishes findings before they appear in the npm advisory DB, and covers some package-level vulnerabilities that are never added to public CVE databases.
Using Snyk
# Install the Snyk CLI
npm install -g snyk
# Authenticate (one-time, opens browser)
snyk auth
# Test your project
snyk test
# Test and fail if high or critical findings
snyk test --severity-threshold=high
# Monitor the project (alerts you when new CVEs affect it)
snyk monitor
Snyk also offers a GitHub App that adds PR checks (similar to Dependabot but using Snyk’s broader database), a web dashboard, and IDE extensions for VS Code, JetBrains, and others.
Snyk’s fix suggestions
Unlike npm audit fix, which applies the minimum version constraint that satisfies the advisory, Snyk’s fix recommendations include context: upgrading from X.Y.Z to X.Y.W introduces a breaking change in the API used by your code. This requires Snyk to analyze your codebase — which it does when you run snyk test with the code present, not just the lockfile.
Cost
Snyk’s free tier covers unlimited public repositories and a capped number of private repository tests per month (confirm current limits at snyk.io, as they change). CLI scanning, the GitHub integration, and IDE extensions are all included in the free tier. Paid tiers add license compliance scanning, custom security policies, container scanning, and higher test limits.
What each tool misses
| Risk class | npm audit | Dependabot | Snyk |
|---|---|---|---|
| CVEs in npm advisory DB | Yes | Yes | Yes |
| CVEs not yet in npm advisory DB | No | Some | Yes |
| Automated fix PRs | No | Yes | Yes |
| Works outside GitHub | Yes | No | Yes |
| License compliance | No | No | Paid tier only |
| Abandoned package detection | No | No | No |
| Typosquatting / name confusion | No | No | No |
| OS-layer Docker vulnerabilities | No | No | Container scanning (paid) |
The shared blind spot across all three tools is typosquatting and abandoned packages. All three look up packages you have already installed in a CVE database. They cannot detect that lodahs (transposing two characters in lodash) is a malicious package — because the malicious package simply does not appear in any CVE database yet, and may never be reported before it exfiltrates credentials from your build environment.
Recommended stacks
Solo developer, personal project on GitHub
Enable Dependabot security updates (one click in repo settings). Run npm audit --audit-level=high in your CI pipeline. This costs nothing and catches the overwhelming majority of published CVEs with automated fixes.
- Dependabot: automated PRs for security patches
- npm audit in CI: fast blocking gate
- DepCheck: paste
package.jsonbefore adding new dependencies
Team project on GitHub, open source or commercial
Add the Snyk GitHub App for PR checks using Snyk’s broader database. Keep Dependabot for automated fix PRs. Run snyk test --severity-threshold=high in CI alongside npm audit.
- Dependabot: automated fix PRs
- Snyk GitHub App: PR checks with broader coverage
- snyk test in CI: fail builds on high/critical
- DepCheck: pre-install paste check for typosquatting signals
Project not on GitHub (GitLab, Bitbucket, self-hosted)
Dependabot is unavailable. Use Snyk’s native integration for your platform (GitLab, Bitbucket, Azure DevOps are all supported). Run npm audit as a fast local check.
- Snyk integration for your platform
- npm audit in CI pipeline
Containerized Node.js (Docker)
Add npm audit --audit-level=high as a Dockerfile RUN step after npm ci. Then scan the built image with Trivy or Docker Scout to catch OS-layer CVEs that no npm tool sees. See the Docker audit guide for the full workflow.
- npm audit inside the Dockerfile build
- Trivy or Docker Scout: image-level OS + npm scan
- Dependabot or Snyk: automated PRs for base image and package updates
node_modules. DepCheck applies typosquatting pattern checks and abandoned-package signals at paste time, before npm install runs.
Check your package.json with DepCheck →
Paste your package.json and see CVE findings alongside typosquatting signals, abandoned package warnings, and license risk — no install, no account, all in the browser.
Frequently asked questions
What is the difference between npm audit and Snyk?
npm audit queries the npm Advisory Database, updated by npm, Inc. Snyk queries its own curated database, which is a superset — it includes findings from NVD, the GitHub Advisory DB, and Snyk’s own research, and often surfaces CVEs days to weeks before they appear in npm’s advisory DB. For the same package, Snyk typically finds more findings. Both provide severity ratings, affected versions, and fix recommendations; Snyk also explains the risk of each suggested fix.
Is Dependabot free?
Yes. Dependabot security alerts and automated security PRs are free for all GitHub repositories — public and private. Dependabot version updates (for keeping all dependencies current, not just patching security issues) are also free. There is no paid Dependabot tier; it is a built-in GitHub feature.
Does npm audit catch all vulnerabilities that Snyk catches?
No. Snyk’s database is broader. In practice, npm audit will miss some CVEs that Snyk flags, particularly for recently disclosed vulnerabilities and less-popular packages. The overlap is substantial, but Snyk is the more comprehensive scanner of the two for CVE coverage.
Can Dependabot detect typosquatting attacks?
No. Dependabot, npm audit, and Snyk all look up installed packages in CVE databases. None of them can detect whether a package name in your package.json is a typosquatting attempt — a malicious package designed to mimic a legitimate name. Typosquatting detection requires name-pattern analysis, not vulnerability database lookups. DepCheck applies pattern checks for common typosquatting techniques (character transposition, homoglyphs, prefix/suffix confusions) when you paste your package.json.
Should I use npm audit, Snyk, and Dependabot together?
For most GitHub-hosted projects, yes. They are complementary: Dependabot handles automated PR creation for security patches with zero ongoing effort, npm audit provides fast CI blocking with no external service, and Snyk adds broader database coverage in PR checks. The three integrate at different points in the workflow (local, GitHub PR, CI pipeline) and use different databases, so running them together closes more of the coverage gap than any one tool alone.
What does npm audit miss that other tools catch?
npm audit misses: (1) CVEs in Snyk’s database not yet added to npm’s advisory DB; (2) license compliance issues — npm audit only checks CVEs; (3) abandoned packages; (4) typosquatting attempts; (5) OS-layer vulnerabilities in Docker images. Each requires a separate tool. DepCheck covers license risk, typosquatting, and abandonment signals for the npm package layer in the browser, without any install.
Does Snyk cost money?
Snyk has a free tier that covers unlimited public repositories and a limited number of private repository tests per month. CLI scanning, the GitHub integration, and IDE extensions are all included in the free tier. Paid tiers add license compliance scanning, custom policies, and higher private-repo test limits. Check snyk.io for current free tier limits, which have changed over time. For most solo developers and small teams, the free tier is sufficient for CVE scanning.
Also in the Copper Bay Labs ship-safety suite
Dependency vulnerability scanning is one layer of your pre-ship checklist. These free tools cover the rest:
Paste your package.json and see vulnerable, abandoned, typosquatted, and risky-license packages flagged by severity — browser-native, no install required.
Paste code or a config file and see exposed API keys and secrets before they reach the repo.
HTTP hardening HardenCheckCheck your security headers and CSP in seconds.
ADA / WCAG ShipSafeScan for ADA/WCAG failures before they become a demand letter.