Sign in

Renovate

@renovatebot.com
24 followers 3 following 54 posts

Open Source Automated Dependency Updates by Mend 22k+ ⭐ - GitHub 👉 github.com/renovatebot/renovate

PostsRepliesMedia
Renovate @renovatebot.com · 29/09/2026
We've announced 1 Critical, 2 High and 1 Moderate security advisories - we recommend you upgrade to a minimum of 44.79.0 (2026-09-10) More info: github.com/renovatebot/...
github.com
[SECURITY]: Announcing 1 Critical, 2 High and 1 Moderate advisories · renovatebot renovate · Discussion #46549
We're announcing 4 GitHub Security Advisories (GHSAs) that affect the Renovate CLI. There are 1 Critical, 2 High and 1 Moderate advisories. It is recommended that you upgrade to a minimum of Renova...
002
Reposted by Renovate
Last2014:ubuntu: @last2014.misskey.systems.ap.brid.gy · 23/09/2026
Renovate botすげえ
011
Renovate @renovatebot.com · 25/09/2026
If you'd like to catch us, drop a note!
000
Renovate @renovatebot.com · 25/09/2026
We're excited to announce that Renovate maintainers Sebastian Poxhofer and Jamie Tanna will be at @linuxfoundation.org's Open Source Summit Europe in Prague in a couple of weeks, and look forward to meeting folks who are there We'll also be at the @openssf.org's Community Day, too
101
Renovate @renovatebot.com · 21/09/2026
Renovate maintainer Jamie Tanna looks back at the last year of being Renovate's Project Lead, and shares some interesting stats about how the project and the wider ecosystem have changed: www.jvt.me/posts/2026/0...
jvt.me
Looking back at my first year as the Renovate Project Lead · Jamie Tanna | Software Engineer
Reviewing some of the key highlights of my last year working as the Renovate Project Lead, and showing some stats about the project, its community and myself.
000
Renovate @renovatebot.com · 09/09/2026
And direct link to the tool: renovate.secustor.dev
renovate.secustor.dev
Renovate Config Debugger
Step through what Renovate actually does with your config — in your browser.
000
Renovate @renovatebot.com · 09/09/2026
Renovate maintainer Sebastian Poxhofer has recently built an awesome way of visualising and debugging through what your Renovate config /actually/ does - secustor.dev/blog/renovat...
secustor.dev
Renovate: It was a packageRule all along
As a Renovate maintainer, the question I answer most often is not “why is Renovate broken?” but “why did Renovate do that with my config?”. The honest answer is usually “because you configured it that...
110
Reposted by Renovate
isabel @isabelroses.com · 24/11/2025
2 beautiful women named "renovate" and "dependabot" messaging me
1523
Renovate @renovatebot.com · 27/08/2026
We've announced 9 High and 1 Moderate security advisories on #Renovate. We recommend updating to 44.14.7 (2026-08-07) at a minimum See github.com/renovatebot/... for more details
github.com
[SECURITY]: Announcing 9 High and 1 Moderate security vulnerabilities in Renovate · renovatebot renovate · Discussion #45495
We're announcing 10 GitHub Security Advisories (GHSAs) that affect the Renovate CLI. There are 9 High and 1 Moderate findings. It is recommended that you upgrade to a minimum of Renovate 44.14.7. T...
000
Reposted by Renovate
Erkan Doğan @erkan.erkandogan.tr.ap.brid.gy · 14/08/2026
Renovate, repolarınızdaki bağımlılıkları otomatik tarayıp güncel sürümler için pull request açan açık kaynak bir bot. Dependabot'tan farkları, kurulumu, örnek renovate.json yapılandırması ve self-hosted CI'da kullanımı bu yazıda.
erkandogan.tr
Renovate Bot Nedir, Neden Kullanmalısınız?
Bağımlılık güncellemeleri, çoğu geliştiricinin ihmal ettiği ama teknik borcun en hızlı biriktiği alanlardan biri. package.json, requirements.txt, Dockerfile, GitHub Actions workflow'ları... hepsi zamanla eskir ve bir gün kritik bir güvenlik açığıyla karşınıza çıkar. Renovate tam olarak bu sorunu çözmek için var. ## Renovate Nedir? Renovate, repolarınızdaki bağımlılıkları otomatik olarak tarayan, güncel sürümleri tespit eden ve her güncelleme için ayrı bir pull request açan açık kaynak bir bottur. Mend (eski adıyla WhiteSource) tarafından geliştirilir ve GitHub, GitLab, Bitbucket, Azure DevOps gibi platformlarda çalışır. Dependabot'a benzese de Renovate çok daha esnek bir yapılandırma sistemine sahiptir. npm, pip, Docker, Terraform, GitHub Actions, Cargo, Go modules dahil onlarca ekosistemi tek bir araçla yönetebilirsiniz. ## Neden Dependabot Değil de Renovate? * **Tek yapılandırma dosyası** — `renovate.json` ile tüm repo genelinde tutarlı kurallar tanımlanır. * **Gruplama desteği** — İlgili paketleri (örneğin tüm `eslint-*` paketlerini) tek bir PR'da toplayabilirsiniz, PR kalabalığı azalır. * **Zamanlama kontrolü** — Güncellemelerin sadece belirli saatlerde/günlerde açılmasını sağlayabilirsiniz (mesai dışı gece build'lerini tetiklememek gibi). * **Otomatik merge** — Minor/patch seviyesindeki düşük riskli güncellemeler için testler geçerse otomatik merge tanımlanabilir. * **Daha geniş ekosistem desteği** — Docker base image'ları, Helm chart'ları, Terraform provider'ları gibi Dependabot'ın zayıf kaldığı alanlarda daha güçlü. ## Kurulum GitHub üzerinde en pratik yol Renovate GitHub App'i kurmak: 1. github.com/apps/renovate adresinden uygulamayı yükleyin. 2. Erişim vermek istediğiniz repoları seçin. 3. Bot ilk taramadan sonra otomatik olarak bir "Configure Renovate" PR'ı açar; bu PR varsayılan `renovate.json` dosyasını içerir. Kendi altyapınızda (self-hosted GitLab, Gitea vb.) çalıştırmak isterseniz `renovate` npm paketini CLI olarak veya resmi Docker image'ı üzerinden CI pipeline'ında da çalıştırabilirsiniz. ## Örnek Yapılandırma json { "$schema": "https://docs.renovatebot.com/renovate-schema.json", "extends": ["config:recommended"], "timezone": "Europe/Istanbul", "schedule": ["after 22:00 every weekday", "every weekend"], "packageRules": [ { "matchUpdateTypes": ["minor", "patch"], "automerge": true }, { "matchPackagePatterns": ["^eslint"], "groupName": "eslint packages" } ], "vulnerabilityAlerts": { "enabled": true, "labels": ["security"] } } Bu örnekte: * Güncellemeler yalnızca mesai dışı saatlerde açılıyor. * Minor ve patch seviyesindeki güncellemeler testler geçerse otomatik birleşiyor. * ESLint ile ilgili paketler tek PR'da gruplanıyor. * Güvenlik açığı bulunan paketler için ayrı, etiketlenmiş uyarılar oluşturuluyor. ## Self-Hosted Ortamlarda Kullanım Proxmox/Docker tabanlı bir altyapıda çalışan projeler için Renovate'i bir cron job veya GitHub Actions scheduled workflow olarak tetiklemek yaygın bir pattern. Örneğin: yaml name: Renovate on: schedule: - cron: '0 3 * * *' workflow_dispatch: jobs: renovate: runs-on: ubuntu-latest steps: - uses: renovatebot/github-action@v40 with: configurationFile: renovate.json token: ${{ secrets.RENOVATE_TOKEN }} Bu, harici bir servise bağımlı olmadan kendi CI altyapınız üzerinden tam kontrol sağlar. ## Pratik İpuçları * **`config:recommended` ile başlayın** — Sıfırdan kural yazmak yerine önerilen preset üzerine küçük özelleştirmeler eklemek daha sürdürülebilir. * **Dashboard PR'ını kapatmayın** — Renovate, tüm bekleyen güncellemeleri listeleyen bir "Dependency Dashboard" issue'su açar; bu genel görünüm için değerlidir. * **Lock file maintenance'ı aktif edin** — `lockFileMaintenance` seçeneği, doğrudan versiyon değişikliği olmasa bile lock dosyasını düzenli tazeler. * **Major güncellemeleri ayrı tutun** — Major sürüm atlamaları genelde breaking change içerir; bunları otomerge dışında bırakıp manuel gözden geçirin. ## Sonuç Renovate, "bağımlılıkları güncel tutma" işini insan hafızasından çıkarıp sürece dönüştürüyor. İlk kurulumu birkaç dakika sürse de, uzun vadede güvenlik açıklarını erken yakalamak ve teknik borcu biriktirmemek açısından kazandırdığı zaman katbekat fazla. Küçük bir yapılandırma dosyasıyla başlayıp ihtiyaca göre kuralları genişletmek en sağlıklı yaklaşım.
011
Renovate @renovatebot.com · 14/08/2026
If you're in the preview for GitHub Actions Lockfiles, but are waiting for Dependabot to ship support for updating them, Renovate's had support since Tuesday :) And a few other things GitHub Actions-y too!
000
Renovate @renovatebot.com · 30/07/2026
You can read more about why this happened + what we've done to reduce the risk of this happening again in github.com/renovatebot/...
github.com
Renovate 44 was accidentally released as a major version (with a non-breaking change) · renovatebot renovate · Discussion #44952
Renovate 44.0.0 was incorrectly released from #44004 due to the BREAKING CHANGE reference in the commit message. To be very clear - the changes in 44.0.0 are not breaking changes. Renovate uses Squ...
000
Renovate @renovatebot.com · 30/07/2026
As folks may have noticed - Renovate 44 was (accidentally) released yesterday with a non-breaking change. Please treat Renovate 44.0.0 as 43.x, and upgrade as normal!
101
Renovate @renovatebot.com · 20/07/2026
Until there are machine-readable ways to denote "finished", we're working on pulling in different signals to take into account - feedback and help appreciated!
000
Renovate @renovatebot.com · 20/07/2026
If it helps, we're still actively working on what we can do to balance between "we think this might be abandoned, you should take a look" and "never show anything"
120
Renovate @renovatebot.com · 13/07/2026
I agree there's more we can be doing to try and avoid this "footgun" by warning users of this more visibly - Jamie
000
Renovate @renovatebot.com · 13/07/2026
Adding a CI stage which checks for all matrix results and then reports status would do what you want here - i.e. github.com/renovatebot/... - it can then be added as a required status check in GitHub
github.com
100
Renovate @renovatebot.com · 13/07/2026
This is more a feature/limitation of GitHub. If you enable auto-merge on any PR that has a status check, but no required status checks, then auto-merge merges immediately, because there's nothing it's waiting for
110
Reposted by Renovate
aly @aly.codes · 25/06/2026
Of all the bots I think renovatebot is the #1 GOAT and Claude is maybe #3
081
Renovate @renovatebot.com · 13/07/2026
Oh dear! Looks like the PR was merged automagically because there's no branch protection on the GitHub side. Renovate expects there to be a required status check when using GitHub's auto-merge functionality (See also: docs.renovatebot.com/configuratio...) - sorry it caused you a red build 💔
docs.renovatebot.com
Configuration Options - Renovate Docs
Configuration Options usable in renovate.json or package.json
110
Renovate @renovatebot.com · 25/06/2026
Should be sorted now 🤞
101
Reposted by Renovate
Jamie Magee @jamiemagee.bsky.social · 21/05/2026
npm staged publishing has shipped 🎉 Your CI can now stage a publish without 2FA, but a human still has to approve it with a hardware key before anything goes live on the registry. Stolen npm tokens stop being game over. Big deal for the Shai-Hulud class of worm. docs.npmjs.com/staged-publi...
docs.npmjs.com
Staged publishing for npm packages | npm Docs
Documentation for the npm registry, website, and command-line interface
143
Renovate @renovatebot.com · 05/05/2026
That's fair - we are also talking about whether we can support Codeberg on Mend-hosted apps, so there's even less to do with onboarding 🤞
010
Renovate @renovatebot.com · 05/05/2026
We're biased, but we'd say we're a better replacement for Dependabot, and we support many more platforms - if you did move over to Codeberg, we support it (when running the Renovate CLI i.e. in CI)!
120
Reposted by Renovate
Andrew Nesbitt @andrewnez.bsky.social · 28/04/2026
GitHub Actions is the weakest link: nesbitt.io/2026/04/28/g...
nesbitt.io
GitHub Actions is the weakest link
Anne Robinson would like a word with .github/workflows
083
Renovate @renovatebot.com · 15/04/2026
The reddit engineering team wrote a great post about how they're using Renovate for their dependency management - very interesting and some good learnings on how they keep things patched at scale! www.reddit.com/r/RedditEng/...
reddit.com
From the RedditEng community on Reddit
Explore this post and more from the RedditEng community
011
Renovate @renovatebot.com · 10/03/2026
Joined on Discord to discuss 👀
030
Renovate @renovatebot.com · 10/03/2026
Renovate is now on endoflife.date/renovate so its even easier to have an at-a-glance way to check whether you're running a supported version or not 🤓
endoflife.date
Renovate CLI
Check end-of-life, release policy and support schedule for Renovate CLI.
030
Renovate @renovatebot.com · 09/03/2026
Learn how #Renovate maintainer @www.jvt.me.web.brid.gy debugs Renovate config changes in this post: www.jvt.me/posts/2026/0...
jvt.me
My workflow for testing Renovate config changes (2026 edition) · Jamie Tanna | Software Engineer
A runthrough of my process for testing more complex Renovate config changes where I want confidence up-front.
000
Reposted by Renovate
Andrew Nesbitt @andrewnez.bsky.social · 04/03/2026
Requested post by @sethmlarson.dev: Package Managers Need to Cool Down nesbitt.io/2026/03/04/p...
nesbitt.io
Package Managers Need to Cool Down
A survey of dependency cooldown support across package managers and update tools.
052
Renovate @renovatebot.com · 23/02/2026
What's on your wishlist? github.com/renovatebot/...
github.com
Feedback wanted: what's on your wishlist? · renovatebot renovate · Discussion #41413
We (the Renovate maintainers) are looking to get an additional gauge of what's important to the community in terms of planned features/bug fixes. In addition to our understanding of the needs of th...
000
Renovate @renovatebot.com · 23/02/2026
What areas you find introduce complexity: github.com/renovatebot/...
github.com
Feedback wanted: complexity in Renovate · renovatebot renovate · Discussion #41412
We (the Renovate maintainers) are seeking community feedback on complexity you may feel when working with Renovate. We're aware that there are areas that both new and experienced folks can find dif...
100
Renovate @renovatebot.com · 23/02/2026
How you find being a new user: github.com/renovatebot/...
github.com
Feedback wanted: Getting started + "week 1" problems · renovatebot renovate · Discussion #41411
We (the Renovate maintainers) are looking to understand the point-of-view for early users of Renovate. (if you have some feedback from the first few weeks of using Renovate, that's also welcome!) F...
100
Renovate @renovatebot.com · 23/02/2026
What you find good and bad about our monorepo support: github.com/renovatebot/...
github.com
Feedback wanted: Renovate's monorepo support · renovatebot renovate · Discussion #41410
We (the Renovate maintainers) are seeking community feedback on how Renovate makes updates to monorepos. We're looking to understand: how you're using Renovate what package ecosystems you're using ...
100
Renovate @renovatebot.com · 23/02/2026
The #Renovate maintainers would like to get some speciifc feedback on a few areas - we'd love to hear from you: github.com/renovatebot/...
github.com
Feedback wanted: monorepos, getting started + "week 1" problems, complexity, and what's on your wishlist? · renovatebot renovate · Discussion #41414
We (the Renovate maintainers) are seeking community feedback on some specific areas, and we'd love y'all to comment on the Discussions: #41410 #41411 #41412 #41413
101
Renovate @renovatebot.com · 20/02/2026
Learn how we're breaking free from @github.com Discussions' limitations for our community triage, in this post from @www.jvt.me.web.brid.gy www.jvt.me/posts/2026/0...
jvt.me
Breaking free from GitHub Discussions' limitations · Jamie Tanna | Software Engineer
How we built our own interface on top of GitHub Discussions to improve triage for Renovate's Open Source community.
000
Renovate @renovatebot.com · 13/02/2026
There are patched versions available for Renovate 42.x and 43.x, and the Mend Renovate Self-Hosted Community and Enterprise edtions (CE and EE)
000
Renovate @renovatebot.com · 13/02/2026
Today we've announced a Moderate security advisory, GHSA-8wc6-vgrq-x6cf *Child processes spawned by Renovate incorrectly have full access to environment variables* github.com/renovatebot/...
github.com
Child processes spawned by Renovate incorrectly have full access to environment variables
When Renovate spawns child processes, their access to environment variables is filtered to an allowlist, to prevent unauthorized access to privileged credentials that the Renovate process has acces...
100
Renovate @renovatebot.com · 12/02/2026
The Mend Developer Platform is now running #Renovate 43! Happy upgrading everyone 🎉
000
Renovate @renovatebot.com · 30/01/2026
Reminder that #Renovate 43 came out yesterday! We landed a few breaking changes, so check out the release notes: github.com/renovatebot/...
github.com
Release 43.0.0 · renovatebot/renovate
43.0.0 (2026-01-29) Breaking changes for 43 Allowlisting required for "unsafe commands" #40684 NoteThis should only affect you if you work with repositories that have a Gradle Wrapper. Prior to Re...
001
Renovate @renovatebot.com · 21/01/2026
Renovate maintainer @www.jvt.me.web.brid.gy writes about some of the things he's learned in the last 100 days since joining #Renovate - some good behind-the-scenes tidbits in here 👀 www.jvt.me/posts/2026/0...
jvt.me
The first 100 days as a Renovate maintainer: the shocking inside view of a popular Open Source project · Jamie Tanna | Software Engineer
Lessons learned from the first 100 days as my role as a Renovate maintainer, and a sneak peek into how the project works behind the scenes.
000
Renovate @renovatebot.com · 13/01/2026
Fixes have been available for 5/6 of them since 2025-05-27, and the final advisory was resolved on 2025-12-31
000
Renovate @renovatebot.com · 13/01/2026
We've announced 6 Moderate Security Advisories, which allow for possible remote code execution, when an attacker has access to a repository's default branch More info: github.com/renovatebot/...
github.com
[SECURITY]: possible remote code execution (with existing access to a repository) · renovatebot renovate · Discussion #40403
Today we are announcing 6 related security advisories: Arbitrary command injection via Gradle Wrapper and malicious distributionUrl (2025-12-28) Arbitrary command injection via kustomize manager an...
111
Renovate @renovatebot.com · 07/01/2026
Why does #Renovate use GitHub Discussions for our user support? Community Manager @www.jvt.me.web.brid.gy took the opportunity to look into the history, off the back of recent discussion around #Ghostty, and wrote an in-depth post about it: github.com/renovatebot/...
github.com
Why do we use GitHub Discussions as our triage process? · renovatebot renovate · Discussion #40306
Over the weekend, there has been some good discussion on Hacker News about how the Ghostty project uses GitHub Discussions for triage purposes, and then promotes the feature request/bug reports int...
010
Renovate @renovatebot.com · 07/01/2026
Mind raising a Discussion to track it? Looks like it might be the fact you're hitting memory limits
100
Renovate @renovatebot.com · 31/12/2025
Are you self-hosting or using Mend's hosted platform?
100
Renovate @renovatebot.com · 17/12/2025
Almost 9 years to the day of creating our first Issue (github.com/renovatebot/...), we've hit our 40,000th Issue/Discussion/PR (github.com/renovatebot/...) on the Renovate GitHub project 🎂
000
Renovate @renovatebot.com · 17/12/2025
FYI: We've changed the `GOSUMDB` environment variable on the Mend-hosted Renovate Cloud infrastructure, which may lead to impact to users with private Go modules. As we've noted in github.com/renovatebot/..., this is due to previously used settings leaving users open to supply chain attacks
github.com
Changes to default `GOSUMDB` environment variable on the Mend Developer Platform (and what it means for private Go modules) · renovatebot renovate · Discussion #40041
NoteThis only affects Renovate Cloud on developer.mend.io (Mend Developer Platform), and does not modify anything for users of the Renovate CLI deployed as part of any self-hosted usage. This also ...
001
Renovate @renovatebot.com · 08/12/2025
Renovate maintainer and community manager @www.jvt.me.web.brid.gy recently spoke to Josh Bressers on the #OpenSourceSecurity podcast all about #Renovate, the "fun" of updating dependencies, and more! opensourcesecurity.io/2025/2025-12...
opensourcesecurity.io
Updating open source dependencies with Jamie Tanna
Josh discusses updating open source dependencies with Jamie Tanna. Jamie works on Renovate which gives them a lot of insight into the challenges of keeping your open source updated. We discuss the cha...
000
Renovate @renovatebot.com · 23/11/2025
We very much agree with this 💜 Safer, slower, upgrades is best!
010