Skip to content

πŸš€ Feature: Switch from Renovate to DependabotΒ #2274

@JoshuaKGoldberg

Description

@JoshuaKGoldberg

Feature Request Checklist

Overview

Renovate is an excellent action/bot/product for keeping. However:

  • Renovate is a third-party product that advertises itself & its parent company
  • The GitHub platform already has Dependabot built-in

I'd previously stuck with Renovate over Dependabot because of Renovate's minimumReleaseAge option. Dependabot didn't have an equivalent. Waiting a minimum number of days to update to a new package is IMO critical for security. Compromised packages typically only last a few hours, but can be devastating within those hours.

Additional Info

#26 had previously moved CTA from Dependabot to Renovate.

Dependabot's cooldown feature was added on July 1st, 2025: https://github.blog/changelog/2025-07-01-dependabot-supports-configuration-of-a-minimum-package-age

I'd missed this until @cylewaitforit had mentioned it in https://bsky.app/profile/cylewaitfor.it/post/3lydwfd5lws2f. Thanks Cyle!

🎁

Metadata

Metadata

Assignees

No one assigned

    Labels

    status: accepting prsPlease, send a pull request to resolve this!type: featureNew enhancement or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions