renovate bot repo for dependency check
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
maximilianbarg d465cc8bb8
All checks were successful
renovate / renovate (push) Successful in 2m21s
ci: update rule for checkout to leave it at v4
2026-10-02 19:34:07 +00:00
.forgejo/workflows feat: update renovate bot version 2026-09-16 14:13:24 +00:00
ci.json5 ci: update rule for checkout to leave it at v4 2026-10-02 19:34:07 +00:00
config.js fix: remove comment 2026-09-16 14:00:31 +00:00
default.json5 feat: add shared renovate presets 2026-10-01 18:12:25 +00:00
docker.json5 feat: add shared renovate presets 2026-10-01 18:12:25 +00:00
kotlin.json5 feat: add shared renovate presets 2026-10-01 18:12:25 +00:00
python.json5 feat: add shared renovate presets 2026-10-01 18:12:25 +00:00
README.md docs: add usage section to readme 2026-10-01 18:21:59 +00:00

renovate-config

renovate bot repo for dependency check

Presets

Preset file Reference Purpose
default.json5 local>maximilianbarg/renovate-config:default.json5 Base config: config:best-practices, automerge for minor/patch/pin/digest, OSV vulnerability alerts, no Docker digest pinning
python.json5 local>maximilianbarg/renovate-config:python.json5 Python/uv rules (pyproject.toml via pep621)
kotlin.json5 local>maximilianbarg/renovate-config:kotlin.json5 Kotlin Multiplatform rules (version catalog, Kotlin+Compose grouping, Gradle wrapper)
docker.json5 local>maximilianbarg/renovate-config:docker.json5 Dockerfile/compose rules (base image, system packages)
ci.json5 local>maximilianbarg/renovate-config:ci.json5 GitHub/Forgejo Actions rules

Usage in other repos

Add a renovate.json5 to the target repository and extend the presets you need. The repo-specific keys (next to extends) always win over the preset values.

Python project

// renovate.json5
{
  $schema: 'https://docs.renovatebot.com/renovate-schema.json',
  extends: [
    'local>maximilianbarg/renovate-config:default.json5',
    'local>maximilianbarg/renovate-config:python.json5',
  ],
  // optional repo-specific overrides, e.g.:
  // labels: ['renovate', 'python-service'],
}

Kotlin Multiplatform project

// renovate.json5
{
  $schema: 'https://docs.renovatebot.com/renovate-schema.json',
  extends: [
    'local>maximilianbarg/renovate-config:default.json5',
    'local>maximilianbarg/renovate-config:kotlin.json5',
    'local>maximilianbarg/renovate-config:docker.json5',
    'local>maximilianbarg/renovate-config:ci.json5',
  ],
}

Pinning to a tag or commit

Pin all presets to the same ref for deterministic updates (tag, branch or commit SHA):

{
  $schema: 'https://docs.renovatebot.com/renovate-schema.json',
  extends: [
    'local>maximilianbarg/renovate-config:default.json5#v1.0.0',
    'local>maximilianbarg/renovate-config:python.json5#v1.0.0',
  ],
}

Notes

  • local> resolves against the platform Renovate runs on, so the same config works on any Forgejo/GitLab/GitHub instance.
  • The .json5 file name must be part of the reference; without it Renovate looks for default.json / <name>.json.
  • Only the first config file found in a repo is used (renovate.json, renovate.json5, renovate.jsonc, …).
  • The Renovate token needs read access to this repository.
  • Setting your own ignorePresets in the repo config replaces the ones from the presets (e.g. the docker:pinDigests ignore in default.json5) — list them again if needed.