Sign in

Renovate

@renovatebot.com
24 followers 3 following 54 posts

Open Source Automated Dependency Updates by Mend 22k+ ⭐ - GitHub 👉 github.com/renovatebot/renovate

PostsRepliesMedia
Renovate @renovatebot.com · 29/09/2026
We've announced 1 Critical, 2 High and 1 Moderate security advisories - we recommend you upgrade to a minimum of 44.79.0 (2026-09-10) More info: github.com/renovatebot/...
github.com
[SECURITY]: Announcing 1 Critical, 2 High and 1 Moderate advisories · renovatebot renovate · Discussion #46549
We're announcing 4 GitHub Security Advisories (GHSAs) that affect the Renovate CLI. There are 1 Critical, 2 High and 1 Moderate advisories. It is recommended that you upgrade to a minimum of Renova...
002
Reposted by Renovate
Last2014:ubuntu: @last2014.misskey.systems.ap.brid.gy · 23/09/2026
Renovate botすげえ
011
Renovate @renovatebot.com · 25/09/2026
We're excited to announce that Renovate maintainers Sebastian Poxhofer and Jamie Tanna will be at @linuxfoundation.org's Open Source Summit Europe in Prague in a couple of weeks, and look forward to meeting folks who are there We'll also be at the @openssf.org's Community Day, too
101
Renovate @renovatebot.com · 21/09/2026
Renovate maintainer Jamie Tanna looks back at the last year of being Renovate's Project Lead, and shares some interesting stats about how the project and the wider ecosystem have changed: www.jvt.me/posts/2026/0...
jvt.me
Looking back at my first year as the Renovate Project Lead · Jamie Tanna | Software Engineer
Reviewing some of the key highlights of my last year working as the Renovate Project Lead, and showing some stats about the project, its community and myself.
000
Renovate @renovatebot.com · 09/09/2026
Renovate maintainer Sebastian Poxhofer has recently built an awesome way of visualising and debugging through what your Renovate config /actually/ does - secustor.dev/blog/renovat...
secustor.dev
Renovate: It was a packageRule all along
As a Renovate maintainer, the question I answer most often is not “why is Renovate broken?” but “why did Renovate do that with my config?”. The honest answer is usually “because you configured it that...
110
Reposted by Renovate
isabel @isabelroses.com · 24/11/2025
2 beautiful women named "renovate" and "dependabot" messaging me
1523
Renovate @renovatebot.com · 27/08/2026
We've announced 9 High and 1 Moderate security advisories on #Renovate. We recommend updating to 44.14.7 (2026-08-07) at a minimum See github.com/renovatebot/... for more details
github.com
[SECURITY]: Announcing 9 High and 1 Moderate security vulnerabilities in Renovate · renovatebot renovate · Discussion #45495
We're announcing 10 GitHub Security Advisories (GHSAs) that affect the Renovate CLI. There are 9 High and 1 Moderate findings. It is recommended that you upgrade to a minimum of Renovate 44.14.7. T...
000
Reposted by Renovate
Erkan Doğan @erkan.erkandogan.tr.ap.brid.gy · 14/08/2026
Renovate, repolarınızdaki bağımlılıkları otomatik tarayıp güncel sürümler için pull request açan açık kaynak bir bot. Dependabot'tan farkları, kurulumu, örnek renovate.json yapılandırması ve self-hosted CI'da kullanımı bu yazıda.
erkandogan.tr
Renovate Bot Nedir, Neden Kullanmalısınız?
Bağımlılık güncellemeleri, çoğu geliştiricinin ihmal ettiği ama teknik borcun en hızlı biriktiği alanlardan biri. package.json, requirements.txt, Dockerfile, GitHub Actions workflow'ları... hepsi zamanla eskir ve bir gün kritik bir güvenlik açığıyla karşınıza çıkar. Renovate tam olarak bu sorunu çözmek için var. ## Renovate Nedir? Renovate, repolarınızdaki bağımlılıkları otomatik olarak tarayan, güncel sürümleri tespit eden ve her güncelleme için ayrı bir pull request açan açık kaynak bir bottur. Mend (eski adıyla WhiteSource) tarafından geliştirilir ve GitHub, GitLab, Bitbucket, Azure DevOps gibi platformlarda çalışır. Dependabot'a benzese de Renovate çok daha esnek bir yapılandırma sistemine sahiptir. npm, pip, Docker, Terraform, GitHub Actions, Cargo, Go modules dahil onlarca ekosistemi tek bir araçla yönetebilirsiniz. ## Neden Dependabot Değil de Renovate? * **Tek yapılandırma dosyası** — `renovate.json` ile tüm repo genelinde tutarlı kurallar tanımlanır. * **Gruplama desteği** — İlgili paketleri (örneğin tüm `eslint-*` paketlerini) tek bir PR'da toplayabilirsiniz, PR kalabalığı azalır. * **Zamanlama kontrolü** — Güncellemelerin sadece belirli saatlerde/günlerde açılmasını sağlayabilirsiniz (mesai dışı gece build'lerini tetiklememek gibi). * **Otomatik merge** — Minor/patch seviyesindeki düşük riskli güncellemeler için testler geçerse otomatik merge tanımlanabilir. * **Daha geniş ekosistem desteği** — Docker base image'ları, Helm chart'ları, Terraform provider'ları gibi Dependabot'ın zayıf kaldığı alanlarda daha güçlü. ## Kurulum GitHub üzerinde en pratik yol Renovate GitHub App'i kurmak: 1. github.com/apps/renovate adresinden uygulamayı yükleyin. 2. Erişim vermek istediğiniz repoları seçin. 3. Bot ilk taramadan sonra otomatik olarak bir "Configure Renovate" PR'ı açar; bu PR varsayılan `renovate.json` dosyasını içerir. Kendi altyapınızda (self-hosted GitLab, Gitea vb.) çalıştırmak isterseniz `renovate` npm paketini CLI olarak veya resmi Docker image'ı üzerinden CI pipeline'ında da çalıştırabilirsiniz. ## Örnek Yapılandırma json { "$schema": "https://docs.renovatebot.com/renovate-schema.json", "extends": ["config:recommended"], "timezone": "Europe/Istanbul", "schedule": ["after 22:00 every weekday", "every weekend"], "packageRules": [ { "matchUpdateTypes": ["minor", "patch"], "automerge": true }, { "matchPackagePatterns": ["^eslint"], "groupName": "eslint packages" } ], "vulnerabilityAlerts": { "enabled": true, "labels": ["security"] } } Bu örnekte: * Güncellemeler yalnızca mesai dışı saatlerde açılıyor. * Minor ve patch seviyesindeki güncellemeler testler geçerse otomatik birleşiyor. * ESLint ile ilgili paketler tek PR'da gruplanıyor. * Güvenlik açığı bulunan paketler için ayrı, etiketlenmiş uyarılar oluşturuluyor. ## Self-Hosted Ortamlarda Kullanım Proxmox/Docker tabanlı bir altyapıda çalışan projeler için Renovate'i bir cron job veya GitHub Actions scheduled workflow olarak tetiklemek yaygın bir pattern. Örneğin: yaml name: Renovate on: schedule: - cron: '0 3 * * *' workflow_dispatch: jobs: renovate: runs-on: ubuntu-latest steps: - uses: renovatebot/github-action@v40 with: configurationFile: renovate.json token: ${{ secrets.RENOVATE_TOKEN }} Bu, harici bir servise bağımlı olmadan kendi CI altyapınız üzerinden tam kontrol sağlar. ## Pratik İpuçları * **`config:recommended` ile başlayın** — Sıfırdan kural yazmak yerine önerilen preset üzerine küçük özelleştirmeler eklemek daha sürdürülebilir. * **Dashboard PR'ını kapatmayın** — Renovate, tüm bekleyen güncellemeleri listeleyen bir "Dependency Dashboard" issue'su açar; bu genel görünüm için değerlidir. * **Lock file maintenance'ı aktif edin** — `lockFileMaintenance` seçeneği, doğrudan versiyon değişikliği olmasa bile lock dosyasını düzenli tazeler. * **Major güncellemeleri ayrı tutun** — Major sürüm atlamaları genelde breaking change içerir; bunları otomerge dışında bırakıp manuel gözden geçirin. ## Sonuç Renovate, "bağımlılıkları güncel tutma" işini insan hafızasından çıkarıp sürece dönüştürüyor. İlk kurulumu birkaç dakika sürse de, uzun vadede güvenlik açıklarını erken yakalamak ve teknik borcu biriktirmemek açısından kazandırdığı zaman katbekat fazla. Küçük bir yapılandırma dosyasıyla başlayıp ihtiyaca göre kuralları genişletmek en sağlıklı yaklaşım.
011
Renovate @renovatebot.com · 14/08/2026
If you're in the preview for GitHub Actions Lockfiles, but are waiting for Dependabot to ship support for updating them, Renovate's had support since Tuesday :) And a few other things GitHub Actions-y too!
000
Renovate @renovatebot.com · 30/07/2026
As folks may have noticed - Renovate 44 was (accidentally) released yesterday with a non-breaking change. Please treat Renovate 44.0.0 as 43.x, and upgrade as normal!
101
Reposted by Renovate
aly @aly.codes · 25/06/2026
Of all the bots I think renovatebot is the #1 GOAT and Claude is maybe #3
081
Reposted by Renovate
Jamie Magee @jamiemagee.bsky.social · 21/05/2026
npm staged publishing has shipped 🎉 Your CI can now stage a publish without 2FA, but a human still has to approve it with a hardware key before anything goes live on the registry. Stolen npm tokens stop being game over. Big deal for the Shai-Hulud class of worm. docs.npmjs.com/staged-publi...
docs.npmjs.com
Staged publishing for npm packages | npm Docs
Documentation for the npm registry, website, and command-line interface
143
Reposted by Renovate
Andrew Nesbitt @andrewnez.bsky.social · 28/04/2026
GitHub Actions is the weakest link: nesbitt.io/2026/04/28/g...
nesbitt.io
GitHub Actions is the weakest link
Anne Robinson would like a word with .github/workflows
083
Renovate @renovatebot.com · 15/04/2026
The reddit engineering team wrote a great post about how they're using Renovate for their dependency management - very interesting and some good learnings on how they keep things patched at scale! www.reddit.com/r/RedditEng/...
reddit.com
From the RedditEng community on Reddit
Explore this post and more from the RedditEng community
011
Renovate @renovatebot.com · 10/03/2026
Renovate is now on endoflife.date/renovate so its even easier to have an at-a-glance way to check whether you're running a supported version or not 🤓
endoflife.date
Renovate CLI
Check end-of-life, release policy and support schedule for Renovate CLI.
030
Renovate @renovatebot.com · 09/03/2026
Learn how #Renovate maintainer @www.jvt.me.web.brid.gy debugs Renovate config changes in this post: www.jvt.me/posts/2026/0...
jvt.me
My workflow for testing Renovate config changes (2026 edition) · Jamie Tanna | Software Engineer
A runthrough of my process for testing more complex Renovate config changes where I want confidence up-front.
000
Reposted by Renovate
Andrew Nesbitt @andrewnez.bsky.social · 04/03/2026
Requested post by @sethmlarson.dev: Package Managers Need to Cool Down nesbitt.io/2026/03/04/p...
nesbitt.io
Package Managers Need to Cool Down
A survey of dependency cooldown support across package managers and update tools.
052
Renovate @renovatebot.com · 23/02/2026
The #Renovate maintainers would like to get some speciifc feedback on a few areas - we'd love to hear from you: github.com/renovatebot/...
github.com
Feedback wanted: monorepos, getting started + "week 1" problems, complexity, and what's on your wishlist? · renovatebot renovate · Discussion #41414
We (the Renovate maintainers) are seeking community feedback on some specific areas, and we'd love y'all to comment on the Discussions: #41410 #41411 #41412 #41413
101
Renovate @renovatebot.com · 20/02/2026
Learn how we're breaking free from @github.com Discussions' limitations for our community triage, in this post from @www.jvt.me.web.brid.gy www.jvt.me/posts/2026/0...
jvt.me
Breaking free from GitHub Discussions' limitations · Jamie Tanna | Software Engineer
How we built our own interface on top of GitHub Discussions to improve triage for Renovate's Open Source community.
000
Renovate @renovatebot.com · 13/02/2026
Today we've announced a Moderate security advisory, GHSA-8wc6-vgrq-x6cf *Child processes spawned by Renovate incorrectly have full access to environment variables* github.com/renovatebot/...
github.com
Child processes spawned by Renovate incorrectly have full access to environment variables
When Renovate spawns child processes, their access to environment variables is filtered to an allowlist, to prevent unauthorized access to privileged credentials that the Renovate process has acces...
100
Renovate @renovatebot.com · 12/02/2026
The Mend Developer Platform is now running #Renovate 43! Happy upgrading everyone 🎉
000
Renovate @renovatebot.com · 30/01/2026
Reminder that #Renovate 43 came out yesterday! We landed a few breaking changes, so check out the release notes: github.com/renovatebot/...
github.com
Release 43.0.0 · renovatebot/renovate
43.0.0 (2026-01-29) Breaking changes for 43 Allowlisting required for "unsafe commands" #40684 NoteThis should only affect you if you work with repositories that have a Gradle Wrapper. Prior to Re...
001
Renovate @renovatebot.com · 21/01/2026
Renovate maintainer @www.jvt.me.web.brid.gy writes about some of the things he's learned in the last 100 days since joining #Renovate - some good behind-the-scenes tidbits in here 👀 www.jvt.me/posts/2026/0...
jvt.me
The first 100 days as a Renovate maintainer: the shocking inside view of a popular Open Source project · Jamie Tanna | Software Engineer
Lessons learned from the first 100 days as my role as a Renovate maintainer, and a sneak peek into how the project works behind the scenes.
000
Renovate @renovatebot.com · 13/01/2026
We've announced 6 Moderate Security Advisories, which allow for possible remote code execution, when an attacker has access to a repository's default branch More info: github.com/renovatebot/...
github.com
[SECURITY]: possible remote code execution (with existing access to a repository) · renovatebot renovate · Discussion #40403
Today we are announcing 6 related security advisories: Arbitrary command injection via Gradle Wrapper and malicious distributionUrl (2025-12-28) Arbitrary command injection via kustomize manager an...
111
Renovate @renovatebot.com · 07/01/2026
Why does #Renovate use GitHub Discussions for our user support? Community Manager @www.jvt.me.web.brid.gy took the opportunity to look into the history, off the back of recent discussion around #Ghostty, and wrote an in-depth post about it: github.com/renovatebot/...
github.com
Why do we use GitHub Discussions as our triage process? · renovatebot renovate · Discussion #40306
Over the weekend, there has been some good discussion on Hacker News about how the Ghostty project uses GitHub Discussions for triage purposes, and then promotes the feature request/bug reports int...
010
Renovate @renovatebot.com · 17/12/2025
Almost 9 years to the day of creating our first Issue (github.com/renovatebot/...), we've hit our 40,000th Issue/Discussion/PR (github.com/renovatebot/...) on the Renovate GitHub project 🎂
000
Renovate @renovatebot.com · 17/12/2025
FYI: We've changed the `GOSUMDB` environment variable on the Mend-hosted Renovate Cloud infrastructure, which may lead to impact to users with private Go modules. As we've noted in github.com/renovatebot/..., this is due to previously used settings leaving users open to supply chain attacks
github.com
Changes to default `GOSUMDB` environment variable on the Mend Developer Platform (and what it means for private Go modules) · renovatebot renovate · Discussion #40041
NoteThis only affects Renovate Cloud on developer.mend.io (Mend Developer Platform), and does not modify anything for users of the Renovate CLI deployed as part of any self-hosted usage. This also ...
001
Renovate @renovatebot.com · 08/12/2025
Renovate maintainer and community manager @www.jvt.me.web.brid.gy recently spoke to Josh Bressers on the #OpenSourceSecurity podcast all about #Renovate, the "fun" of updating dependencies, and more! opensourcesecurity.io/2025/2025-12...
opensourcesecurity.io
Updating open source dependencies with Jamie Tanna
Josh discusses updating open source dependencies with Jamie Tanna. Jamie works on Renovate which gives them a lot of insight into the challenges of keeping your open source updated. We discuss the cha...
000
Renovate @renovatebot.com · 23/11/2025
We very much agree with this 💜 Safer, slower, upgrades is best!
010
Renovate @renovatebot.com · 18/11/2025
Today we've released #Renovate v42 onto the Mend Developer Platform (developer.mend.io) so y'all will start being protected by some of the big changes we've made - check out the details below:
100
Renovate @renovatebot.com · 06/11/2025
#Renovate 42 is now out 🚀 Our latest major release with a number of breaking changes is released, most notably:
100
Renovate @renovatebot.com · 05/11/2025
We were very excited to see last week we hit 20,000(!) GitHub Stars on the #Renovate project 🚀 Thanks to our amazing community + users 🤗
A graph showing the history of GitHub Stars for the Renovate project over the years, generated by star-history.com. It shows a rise to just over 20,000 stars this last week, steadily increasing over the years, back from its starting point in 2017
001
Renovate @renovatebot.com · 24/10/2025
We're gearing up for the next release of #Renovate in a couple of weeks 👀 github.com/renovatebot/...
github.com
v42 is coming · renovatebot renovate · Discussion #38841
I wanted to drop out a note to let folks know that on roughly 2025-11-06, we will release Renovate v42. As a major release, there will be a number of breaking changes. These breaking changes are cu...
000
Renovate @renovatebot.com · 08/10/2025
Announcing improvements on communicating large changes to Mend #Renovate (CLI/Cloud): github.com/renovatebot/...
github.com
Announcing improvements on communicating large changes to Mend Renovate (CLI/Cloud) · renovatebot renovate · Discussion #38462
Why do we need to make improvements? In #37842, we were looking to perform a wide-reaching change, which we've decided not to move forward with. We received some really valuable feedback from the c...
002