Renovate
Renovate is an open source dependency update bot you can self-host — a Dependabot alternative that scans your repos for outdated packages and opens pull requests to upgrade them across 90+ package managers and every major Git platform.
What is Renovate?
Renovate is an open source bot that keeps your project dependencies up to date automatically. It scans your repositories for package files, finds newer versions of the libraries you depend on, and opens pull requests to upgrade them — with changelogs, release notes, and adoption data attached so you can review each bump with context.
What is Renovate best for?
Teams that want automated, low-noise dependency updates across more than just GitHub — and anyone who has outgrown a simpler updater and needs fine-grained control over grouping, scheduling, and auto-merge rules. It’s especially strong for polyglot codebases and monorepos where dozens of package managers coexist.
What can Renovate do?
- Update dependencies across 90+ package managers — npm, Python, Go, Java/Maven, .NET, Ruby, Docker, and more
- Run on GitHub, GitLab, Bitbucket, Azure DevOps, AWS CodeCommit, Gitea, Forgejo, and Gerrit
- Group related updates into single PRs with community-maintained monorepo presets
- Show merge confidence badges (age, adoption, pass rate) to signal how safe an upgrade is
- Auto-merge low-risk updates and schedule PRs to avoid weekday noise
- Give you a Dependency Dashboard issue that tracks every pending and pinned update in one place
Is Renovate free?
Yes — Renovate is free and open source under AGPL-3.0. You can self-host it at no cost via npm, Docker, a GitHub Action, or a GitLab Runner, and the Mend-hosted app for GitHub.com and Bitbucket Cloud is also free. Mend sells a paid Renovate Enterprise edition with a management UI, org-wide controls, and support, but the core bot costs nothing.
Where does Renovate fall short?
- Its configuration surface is huge. The power to control grouping, scheduling, and auto-merge comes with a steep learning curve, and dialing in
renovate.jsonto avoid a flood of PRs takes real effort. - It was relicensed from MIT to the copyleft AGPL-3.0. That’s fine for most self-hosting, but it’s more restrictive than Dependabot’s MIT license if you plan to build a service around the code.
- Unlike Dependabot, it isn’t built into GitHub — you install the app or self-host, so there’s a setup step Dependabot users skip entirely.
What does Renovate replace?
Renovate is a self-hosted, cross-platform alternative to Dependabot, GitHub’s built-in updater, and covers much of the automated dependency-update job that a security platform like Snyk charges for. You run it wherever your code lives instead of being tied to one vendor’s cloud.
FAQ
Is Renovate open source? Yes. The core bot is licensed under AGPL-3.0-only and developed in the open by Mend. Only Renovate’s Enterprise edition and management add-ons are proprietary.
Can I self-host Renovate for free? Yes. Self-hosting is free via npm, Docker, a GitHub Action, or a GitLab Runner — you only pay for the machine or CI minutes it runs on.
Is Renovate a good Dependabot alternative? For most teams, yes — it supports far more package managers and Git platforms and offers deeper control. Dependabot wins only on zero-setup simplicity if you’re all-in on GitHub.
What do I need to run Renovate? A supported Git platform and either the hosted app or a runtime for self-hosting — Node.js, Docker, or a CI runner — plus a token so the bot can read repos and open PRs.