Dependabot is now free
nimbleindustries.io
nimbleindustries.io
( no affiliation just a happy user )
Not even the top 15 [1], they are 16th.
You don't want stuff changing of its own accord without a corresponding commit in your own repo. Especially not on a per-installation basis. Sometimes people get SemVer wrong. Or you may be bit by the bug that caused a patch release on one machine, and want to reproduce the issue on another.
But the downside of pinning versions is that you don't get the patch release in dependency A until you go to update/install unrelated dependency B. For a mature project, that could be never, or only by giant leaps every few months or years. Tools like this keep your version locks consistently up to date.
This is on top of the benefits of upgrading pinned-but-compatible versions which someone else covered.
I personally think a standardized method of providing or writing change logs is the next iteration of semvar.
Currently it’s a hot mess of using a changelog file, release notes, private website, all in unstructured text format, even if generated from commits.
There's been more than a few times that I've seen a new feature pop up in a changelog that ends up being super helpful for something I'm working on. And being able to track deprecation warnings as they're introduced means being able to gradually keep my usage of a library up to date, and avoiding painful upgrades later.
This sounds like "why do we need cooks when we have cooking books".
Semver is a policy/idea. It doesn't actually do anything. Dependabot lets you know about updates and tries to do them for you.
Why does it need permissions to read and write code? If it's a public repository, anyone can read. It shouldn't be modifying code. At best it should be submitting patch requests.
Giving Microsoft write permission on open source code is dangerous. They might decide that they need to inject "telemetry". As they've done to non-Microsoft applications on Windows.
The part of your post about telemetry is FUD and probably why you are being downvoted. These are pull requests you can review before merging.