Skip to content

chore: migrate dependency updates from Dependabot to Renovate - #152

Closed
ivorisoutdoors wants to merge 1 commit into
mainfrom
chore/migrate-dependabot-to-renovate-r2
Closed

ivorisoutdoors wants to merge 1 commit into
mainfrom
chore/migrate-dependabot-to-renovate-r2

Conversation

@ivorisoutdoors

Copy link
Copy Markdown
Contributor

What changes for dependency PRs

  • Who opens them: the org Renovate GitHub App instead of dependabot[bot].
  • When: monthly on the 1st → monthly on the 1st (UTC), unchanged. Tick an update in the Dependency Dashboard issue to get it early.
  • Grouping: one github-actions dependencies PR, the same scope as Dependabot's actions group. Major updates land in the same PR.
  • Coverage: newly updated: none. No longer updated: none.
  • Versions: Renovate bumps the range in the manifest, not only the lockfile. It leaves engines, the Go go directive, requires-python, and Terraform required_version alone.
  • Limits: no cap on open PRs.
  • Labels and commits: renovate and dependencies labels; semantic commit messages (chore(deps): ... instead of Dependabot's ci: ...).
  • Dropped: commit-message.prefix: ci: the repo has no release tooling that reads commit types, and the preset uses semantic commits. groups.actions (patterns: ["*"]): the org default github-actions dependencies PR already groups every action. directory: /: Renovate scans the whole repo.
  • Security updates: Dependabot security updates are a repo setting and keep running if enabled.

After merging

  • Add the renovate topic so the org Renovate operator picks up this repo: send @Botzo repo topic add renovate to articulate/docker-node in Slack. Nothing opens until the topic is set. Re-running it is harmless.

Notes

  • The dockerfile manager is off ("dockerfile": { "enabled": false }) because each image pins its base-image major on purpose, so Renovate base-image updates would be unwanted cross-major bumps. Dependabot did not update the Dockerfiles either.
  • Judgment call: .github/workflows/auto-merge.yaml approves and auto-merges PRs opened by dependabot[bot] or articulate-automation[bot]. This PR does not edit it. Renovate PRs auto-merge only if the org Renovate App's login is one of those two, and the dependabot[bot] clause now matches only security-update PRs. The owner decides whether to update the login check.

@ivorisoutdoors

Copy link
Copy Markdown
Contributor Author

Superseded by a rerun on chore/migrate-dependabot-to-renovate-r3 with the updated migrate-dependabot skill.

@ivorisoutdoors
ivorisoutdoors deleted the chore/migrate-dependabot-to-renovate-r2 branch October 9, 2026 18:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant