Import dependencies
Paste the dependency file or a clean list of packages. We extract names and versions for review.
Package managers
Track changelogs and release notes across the ecosystems you ship on.
Each manager page shows the formats we accept and a short setup guide. Start with the file you already keep in your repo.
Every page includes formats, import steps and a short FAQ.
Track frontend and tooling dependencies with release notes and alert rules.
Platforms: Node.js, web, tooling
Primary file: package.json
Track backend dependencies with clear changelog summaries and alert rules.
Platforms: PHP, Laravel, Symfony
Primary file: composer.json
Track data and automation dependencies with release notes and security signals.
Platforms: Python, data, automation
Primary file: requirements.txt
Track systems dependencies with release notes and breaking change signals.
Platforms: Rust, CLI, systems
Primary file: Cargo.toml
Track service dependencies with release notes and security signals.
Platforms: Go, backend, tooling
Primary file: go.mod
Track library dependencies with changelog highlights and version signals.
Platforms: Java, Kotlin, JVM
Primary file: pom.xml
Track build dependencies across modules with release and security alerts.
Platforms: Android, Java, Kotlin
Primary file: build.gradle
Track framework dependencies with changelog highlights and update alerts.
Platforms: .NET, C#, Unity
Primary file: .csproj
Track web app dependencies with changelog highlights and alerts.
Platforms: Ruby, Rails
Primary file: Gemfile
Track mobile dependencies with changelog highlights and update alerts.
Platforms: iOS, macOS
Primary file: Podfile
Track mobile and desktop dependencies with release notes and breaking change signals.
Platforms: iOS, macOS, Swift
Primary file: Package.swift
Import once and we handle the rest.
Paste the dependency file or a clean list of packages. We extract names and versions for review.
We scan changelogs, release notes and security advisories. Breaking change signals appear when available.
Alerts respect your version ranges and notification rules. You decide which releases trigger notifications.
Quick answers about package manager monitoring.
Not yet. We monitor public registries only.
No. Use the dependency file or a list with versions. We do not need lockfiles.
Not yet. One monitor uses one package manager. Use multiple monitors if you need more.