Skip to content

Move dependency updates from Dependabot to Renovate - #680

Open
frenck wants to merge 1 commit into
masterfrom
frenck/renovate
Open

frenck wants to merge 1 commit into
masterfrom
frenck/renovate

Conversation

@frenck

@frenck frenck commented Sep 27, 2026 •

Copy link
Copy Markdown
Member

This moves the dependency updates of this repository from Dependabot to Renovate, which already handles this for core, frontend, android and several other Home Assistant repositories. It adds .github/renovate.json and removes .github/dependabot.yml.

  • Go modules, with go mod tidy after each update so go.mod and go.sum stay clean, and the go label Dependabot applied.
  • The golang.org/x/* modules are grouped. They are released together every month, and came in as separate PRs so far (golang.org/x/term alone eight times this year).
  • The Go version in go.mod is left alone. Moving to a new Go release is a deliberate change, together with GOLANG_VERSION in the workflows.
  • GitHub Actions, with the github_actions label. Actions are pinned to commit SHAs (with the version as a comment) through helpers:pinGitHubActionDigests, and kept up to date that way. Our own actions that follow a branch, like home-assistant/actions@master, keep floating; pinning those would mean a digest PR in every repository for every change to them. Runner labels and action version inputs are left alone, as Dependabot never updated those.
  • A 3 day minimum release age, so a freshly published (and possibly broken or compromised) release isn't picked up right away.

Tested with a local Renovate run (--platform=local --dry-run=full). The Go modules are all up to date, so once active, expect two PRs: a "Pin dependencies" PR that pins the actions (checkout, setup-go, golangci-lint, release-drafter and codespell), and an update of codespell-project/actions-codespell from v2.2 to v2.4.3. It was on the floating v2.2 tag, which Dependabot never updated. Also validated with renovate-config-validator --strict.

Summary by CodeRabbit

  • Chores
    • Dependency update automation now uses Renovate instead of Dependabot for GitHub Actions and Go modules. Updates are held for at least three days after release; related Go module updates may be grouped, and Go modules are tidied after updates. Renovate also applies dependency labels and excludes certain toolchain, runner, and development-branch digest updates.

@frenck frenck added the dependencies Pull requests that update a dependency file label Sep 27, 2026
@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: be753af9-4958-4ab6-82ad-2b471ec0dac3

📥 Commits

Reviewing files that changed from the base of the PR and between 08e8bb4 and 1a63b25.

📒 Files selected for processing (2)
  • .github/dependabot.yml
  • .github/renovate.json
💤 Files with no reviewable changes (1)
  • .github/dependabot.yml

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.


📝 Walkthrough

Walkthrough

The pull request removes the Dependabot configuration and adds Renovate configuration for GitHub Actions and Go modules. The new settings define update timing, post-update behavior, labels, package grouping, excluded dependency types, and digest-pinning rules.

Changes

Dependency update configuration

Layer / File(s) Summary
Configure Renovate dependency updates
.github/dependabot.yml, .github/renovate.json
Removes the Dependabot schedules and pull request limits. Adds Renovate settings for GitHub Actions and Go modules, including a three-day minimum release age, Go module tidying, labels, grouping, excluded dependency types, and digest-pinning rules.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 1a63b

This changes dependency updates to Renovate while preserving the existing GitHub Actions and Go module coverage. Grant the Renovate app repository access after merging; no identified issue otherwise blocks merging.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: replacing Dependabot with Renovate for dependency updates.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cla-signed dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant