Discover / Security

Renovate

by renovatebotTypeScript

Automated dependency updates with security-aware scheduling.

Toolstable

Maturity: stable because 10y old, 44.4.6 released 3d ago. Derived from release and commit history, not a rating.

Stars
22k
Forks
3.2k
Downloads / mo
2.1M
Last commit
2026-08-03
License
AGPL-3.0
Open issues
1.3k

Market and trust evidence

Edition not yet matched

No exact skills.sh identity match is available for this repository. Repository adoption and freshness remain visible above; install momentum is not inferred.

Trust analysis is a screening signal, not a security warranty. Read the ranking and trust methodology.

In practice

Written by AI from this repository’s README · high confidence

Dependency versions fall behind because checking and bumping them by hand across repositories is tedious.

Use it when

When you want scheduled dependency update pull requests on GitHub, GitLab, Bitbucket or Azure DevOps.

Not the right pick when

Running it well needs a scheduling system, and the cloud hosted app supports only GitHub.com and Bitbucket Cloud.

Capabilities

  • Delivers update pull requests directly to your repository
  • Discovers relevant package files automatically
  • Shows age, adoption, pass rate and merge confidence data
  • Supports over 90 different package managers
  • Runs on GitHub, GitLab, Bitbucket, Azure DevOps and more
  • GitHub Action and GitLab Runner pipeline options

Cost: Open source with a paid cloud option

Install

Derived from the published package name in the repository, not from a model.

Video walkthroughs

Third-party YouTube uploads matched to this tool by title, channel and repository name on 2026-08-03. Not made, reviewed or endorsed by SkillPilot. View counts and publish months are as of the match date and the month is approximate. Nothing loads from YouTube until you press play.

What the repository ships

Ships CLAUDE.mdHas testsHas docsSecurity policyCI configured

Detected from the actual files in the repository root.

Latest release 44.4.6

Published 2026-07-31

44.4.6 (2026-07-31)

Bug Fixes

  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.78.7 (main) (#44986) (d1d254c)

Tags

README

Mend Renovate CLI banner

License: AGPL-3.0-only

codecov

Renovate enabled

Build status

Docker Pulls

OpenSSF Scorecard

What is the Mend Renovate CLI?

Renovate is an automated dependency update tool.

It helps to update dependencies in your code without needing to do it manually.

When Renovate runs on your repo, it looks for references to dependencies (both public and private) and, if there are newer versions available, Renovate can create pull requests to update your versions automatically.

Features

  • Delivers update PRs directly to your repo
  • Relevant package files are discovered automatically
  • Pull Requests automatically generated in your repo
  • Provides useful information to help you decide which updates to accept (age, adoption, pass rates, merge confidence)
  • Highly configurable and flexible to fit in with your needs and repository standards
  • Largest collection of languages and platforms (listed below)
  • Connects with private repositories and package registries

Languages

Renovate can provide updates for most popular languages, platforms, and registries including: npm, Java, Python, .NET, Scala, Ruby, Go, Docker and more.

Supports over 90 different package managers.

Platforms

Renovate updates code repositories on the following platforms: GitHub, GitLab, Bitbucket, Azure DevOps, AWS Code Commit (experimental), Gitea, Forgejo, Gerrit (experimental), SCM-Manager (experimental)

Ways to run Renovate

The most effective way to run Renovate is to use an automated job scheduling system that regularly runs Renovate on all enabled repositories and responds with priority to user activity.

Mend offers cloud-hosted and self-hosted solutions.

See the options below.

Mend Renovate Community (Cloud-Hosted)

Supports: GitHub.com, Bitbucket Cloud

Hosted by Mend.io.

No setup is needed.

Community plan available (Free)

  • GitHub Cloud: Install the Renovate Cloud-Hosted App on your GitHub org, then select the repos to enable
  • Bitbucket Cloud: Add the Mend App to your Workspace, then add the Mend Renovate user to the projects you want to enable

Mend Renovate Community (Self-hosted)

Supports: GitHub, GitLab, Bitbucket Data Center

Install and run your own Renovate server.

Access internal packages.

Other ways to run Renovate

If you can’t use a pre-built job scheduling system, or want to build your own, the following options are available:

Run Renovate on your Pipeline

Mend provides a _GitHub Action_ or a _GitLab Runner_ to help you run Renovate as a CI pipeline job.

_Note: This extension is created and maintained personally by a Renovate developer/user. Support requests for the extension will not be answered directly in the main Renovate repository._

Run Renovate CLI

There are several ways to run the Renovate CLI directly.

See docs: Running Renovate for all options.

Supports: all platforms

For additional community-maintained options, see the Community Tools page.

Docs

More about Renovate

Renovate Docs

Comparisons

Get involved

Issues and Discussions

Please open a Discussion to get help, suggest a new feature, or to report a bug.

We only want maintainers to open Issues.

Contributing

To contribute to Renovate, or run a local copy, please read the contributing guidelines.

Contact and Social Media

The Renovate project is proudly supported and actively maintained by Mend.io.

  • Contact Mend.io for commercial support questions.

Follow us on:

Security / Disclosure

If you find any bug with Renovate that may be a security problem, please report it through the GitHub Security Advisories process.

This way we can evaluate the bug and hopefully fix it before it gets abused.

Please give us enough time to investigate the bug before you report it anywhere else.

If you would like to discuss a potential finding before raising the Advisory, then e-mail us at: renovate-disclosure@mend.io.

Related tools