Outdated dependencies are security vulnerabilities waiting to happen. Renovate watches your repos and creates pull requests for every update — automatically, on schedule, with changelogs and compatibility scores.
How Renovate Works
Renovate scans your repo for dependency files (package.json, requirements.txt, Dockerfile, terraform.tf, Chart.yaml, etc.), checks for updates, and creates one PR per update:
Renovate scans repo → finds outdated dep → creates PR → CI runs → you merge (or automerge)Setup
GitHub App (easiest)
Install the Renovate GitHub App on your repos. Add a config file:
// renovate.json
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": ["config:recommended"]
}That is the minimal setup. Renovate starts creating PRs within minutes.
Self-Hosted
# Run as a Docker container
docker run --rm \
-e RENOVATE_TOKEN=ghp_xxx \
-e RENOVATE_REPOSITORIES='["myorg/myapp"]' \
renovate/renovateMaster this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Configuration
Group Related Updates
{
"packageRules": [
{
"matchPackagePatterns": ["^@types/"],
"groupName": "TypeScript type definitions"
},
{
"matchPackagePatterns": ["eslint"],
"groupName": "ESLint and plugins"
},
{
"matchManagers": ["dockerfile"],
"groupName": "Docker base images"
}
]
}Instead of 15 separate PRs for ESLint plugins, you get one.
Automerge Safe Updates
{
"packageRules": [
{
"matchUpdateTypes": ["patch"],
"automerge": true
},
{
"matchPackagePatterns": ["^@types/"],
"automerge": true
},
{
"matchUpdateTypes": ["minor"],
"matchPackagePatterns": ["^eslint"],
"automerge": true
}
]
}Patch updates automerge after CI passes. Type definitions automerge. Minor ESLint updates automerge. Major versions require manual review.
Schedule Updates
{
"schedule": ["before 8am on Monday"],
"timezone": "Europe/Rome"
}All PRs created Monday morning. Review and merge during the week.
Pin Dependencies
{
"rangeStrategy": "pin"
}Converts ^1.2.3 to 1.2.3. Every update becomes an explicit PR. Maximum reproducibility.
What Renovate Updates
| File | Package Manager |
|---|---|
package.json | npm, yarn, pnpm |
requirements.txt | pip |
Pipfile | pipenv |
pyproject.toml | poetry |
go.mod | Go modules |
Dockerfile | Docker images |
docker-compose.yml | Docker images |
.terraform.lock.hcl | Terraform providers |
Chart.yaml | Helm charts |
.github/workflows/*.yml | GitHub Actions |
Gemfile | Ruby gems |
Over 70 package managers supported.
Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →PR Quality
Each Renovate PR includes:
- Version diff:
1.2.3 → 1.3.0 - Changelog: Extracted from GitHub releases
- Merge confidence: Based on adoption rate and age
- CI status: Your tests run automatically
## [1.3.0](https://github.com/pkg/releases/tag/v1.3.0)
### Features
- Added streaming support
### Bug Fixes
- Fixed memory leak in connection pool
**Merge confidence**: High (87% of users updated within 3 days)Renovate vs Dependabot
| Feature | Renovate | Dependabot |
|---|---|---|
| Managers | 70+ | ~15 |
| Grouping | Flexible rules | Limited |
| Automerge | Built-in | Requires GitHub Actions |
| Scheduling | Cron-like | Weekly/daily/monthly |
| Config | Highly customizable | Basic |
| Self-hosted | Yes | No (GitHub only) |
Renovate is more powerful and flexible. Dependabot is simpler and built into GitHub. For polyglot repos or complex dependency strategies, Renovate wins.
---
Ready to go deeper? Automate your development workflows with hands-on courses at CopyPasteLearn.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Mise Dev Tool Version Manager
Mise (formerly rtx) manages tool versions per project. Replace nvm, pyenv, rbenv, and tfenv with one tool. Learn how to set up mise for polyglot development.
Environment Variables Best Practices
Handle environment variables correctly. Dotenv files, Docker secrets, Kubernetes ConfigMaps, twelve-factor methodology, and security pitfalls.
Python for DevOps Automation
Python for DevOps automation. HTTP API clients, file processing, AWS boto3, subprocess management, and CLI tools for infrastructure.
Rocky Linux vs AlmaLinux 2026
A practical comparison of Rocky Linux and AlmaLinux — the two leading RHEL-compatible distributions. Which CentOS successor should you choose?
Rook Ceph Kubernetes Storage Guide
Rook deploys Ceph distributed storage on Kubernetes for block, file, and object storage. Learn how to set up Rook-Ceph for persistent volumes, shared.
Root Cause Analysis for DevOps
Apply Root Cause Analysis to DevOps incidents. The 5 Whys, fishbone diagrams, blameless postmortems, and automated RCA tooling.
Explore topics
Browse more articles on the topics covered here.