Renovate Config Generator
Generate a renovate.json with grouping, scheduling, automerge rules and stability days tuned to how much update noise your team can absorb.
Last reviewed by the Radiatus Cloud team
Want this automated for your stack?
We build CI/CD, Kubernetes & IaC pipelines that scale.
The failure mode is noise, not risk
Automated dependency updates fail when they produce more pull requests than anyone reads. A repository with two hundred dependencies and no grouping generates a wall of individual PRs, the team stops looking, and the security updates that mattered are buried among patch bumps to development tooling. Grouping related updates, limiting concurrency and scheduling the noisy ones outside working hours is what keeps the mechanism useful, and it is more important than any individual setting.
Automerge only where the tests are trustworthy
Automerging development dependency patches and lockfile maintenance removes most of the volume at very little risk, because a broken formatter or test library fails the build immediately. Automerging production dependency minors is a different proposition and depends entirely on how much your test suite actually verifies. A team automerging into a repository with thin tests is not saving time, it is deferring the discovery of a break to production.
Stability days blunt the supply chain window
The minimumReleaseAge setting delays an update until a version has been public for a set period, which means a compromised or immediately yanked release is usually withdrawn before Renovate proposes it. Several high profile npm supply chain incidents were caught within hours, well inside a three day window. It costs nothing except a short delay on updates that are rarely urgent, and it should be paired with an exception so genuine security advisories still arrive immediately.
Related tools
- CI/CD Security Gap Analyzer — Checklist based analyzer for CI/CD pipeline security gaps.
- Docker Security Scanner — A new tool extracted from the codebase.
- Terraform Scanner — A new tool extracted from the codebase.
- SQL Formatter — Format and indent SQL queries for readability. Handles joins, subqueries and CTEs, supports common dialects, and runs entirely in your browser.
Frequently Asked Questions
How do I stop Renovate flooding the repository?
Group related updates with packageRules, set prConcurrentLimit and prHourlyLimit, and schedule non urgent updates outside working hours. A dependency dashboard issue also lets you see everything pending without a PR for each one.
Should I enable automerge?
For development dependency patches and lockfile maintenance, generally yes: a break fails the build immediately and the risk is low. For production dependencies it depends entirely on how much your test suite verifies, and automerging into thin tests defers discovery to production rather than saving time.
What does minimumReleaseAge do?
It waits until a version has been public for a set period before proposing it, so a compromised or quickly yanked release is usually withdrawn first. Several npm supply chain incidents were caught within hours, well inside a three day window. Pair it with an exception for security advisories.
How do I handle major version updates?
Separate them from minors and patches so they get individual review, and consider requiring an explicit dependency dashboard approval so they only open when someone asks. Majors carry breaking changes by definition and should not arrive alongside routine bumps.
Renovate or Dependabot?
Renovate offers considerably more control over grouping, scheduling and automerge, and supports more ecosystems. Dependabot is built into GitHub with no setup. If the volume of updates is a problem, Renovate is the tool with the settings to fix it.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Choose your ecosystems and update appetite to generate a Renovate configuration.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.