DevOps

Renovate Config Generator

Generate a renovate.json with grouping, scheduling, automerge rules and stability days tuned to how much update noise your team can absorb.

Last reviewed by the Radiatus Cloud team

Configuration appears here.

Want this automated for your stack?

We build CI/CD, Kubernetes & IaC pipelines that scale.

Talk to an engineer

The failure mode is noise, not risk

Automated dependency updates fail when they produce more pull requests than anyone reads. A repository with two hundred dependencies and no grouping generates a wall of individual PRs, the team stops looking, and the security updates that mattered are buried among patch bumps to development tooling. Grouping related updates, limiting concurrency and scheduling the noisy ones outside working hours is what keeps the mechanism useful, and it is more important than any individual setting.

Automerge only where the tests are trustworthy

Automerging development dependency patches and lockfile maintenance removes most of the volume at very little risk, because a broken formatter or test library fails the build immediately. Automerging production dependency minors is a different proposition and depends entirely on how much your test suite actually verifies. A team automerging into a repository with thin tests is not saving time, it is deferring the discovery of a break to production.

Stability days blunt the supply chain window

The minimumReleaseAge setting delays an update until a version has been public for a set period, which means a compromised or immediately yanked release is usually withdrawn before Renovate proposes it. Several high profile npm supply chain incidents were caught within hours, well inside a three day window. It costs nothing except a short delay on updates that are rarely urgent, and it should be paired with an exception so genuine security advisories still arrive immediately.

Related tools

Frequently Asked Questions

How do I stop Renovate flooding the repository?

Group related updates with packageRules, set prConcurrentLimit and prHourlyLimit, and schedule non urgent updates outside working hours. A dependency dashboard issue also lets you see everything pending without a PR for each one.

Should I enable automerge?

For development dependency patches and lockfile maintenance, generally yes: a break fails the build immediately and the risk is low. For production dependencies it depends entirely on how much your test suite verifies, and automerging into thin tests defers discovery to production rather than saving time.

What does minimumReleaseAge do?

It waits until a version has been public for a set period before proposing it, so a compromised or quickly yanked release is usually withdrawn first. Several npm supply chain incidents were caught within hours, well inside a three day window. Pair it with an exception for security advisories.

How do I handle major version updates?

Separate them from minors and patches so they get individual review, and consider requiring an explicit dependency dashboard approval so they only open when someone asks. Majors carry breaking changes by definition and should not arrive alongside routine bumps.

Renovate or Dependabot?

Renovate offers considerably more control over grouping, scheduling and automerge, and supports more ecosystems. Dependabot is built into GitHub with no setup. If the volume of updates is a problem, Renovate is the tool with the settings to fix it.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Choose your ecosystems and update appetite to generate a Renovate configuration.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.