Problem
Dependabot has no shared configuration: no extends, no org-wide dependabot.yml. Every repo carries its own copy of .github/dependabot.yml, seeded from the dependabot.yml template. A policy that should apply everywhere has to be swept into each repo and then drifts.
The case that surfaced this: TypeScript 7.0 breaks coverage measurement, so every repo needs to ignore 7.0.x while still accepting 7.1, which is planned to fix it (wisp#21 carries the ignore for wisp today). Most other org configuration is centrally controlled with per-repo overrides, and dependency policy is the exception.
Proposal
Move dependency updates to Renovate. The hosted Mend Renovate GitHub app is free for public and private repositories (free tier: one concurrent job on a four-hour cycle), and self-hosting is also free.
- One shared preset in this repo (for example
renovate.json or default.json, consumed as github>CLDMV/.github) holds the org policy: schedule, target-branch (next), commit prefix, labels, the vitest-family grouping, and package rules such as the TypeScript 7.0.x ignore.
- Each repo's
renovate.json is {"extends": ["github>CLDMV/.github"]} plus only its own overrides.
- A policy change lands once in the preset and reaches every repo without a sweep.
What changes in the v4 flow
The flow is built around Dependabot, so this is a migration, not a config swap:
dependabot-auto-merge and its action key off Dependabot's actor and metadata.
dependabot-recreate uses Dependabot's @dependabot recreate command.
- The security-PR redirect to
hotfixes (redirect-hotfix-pr, described in release-flow-v4.md) detects a Dependabot PR whose base differs from the configured routine target-branch. Renovate needs an equivalent: vulnerability-alert PRs routed to hotfixes through vulnerabilityAlerts and packageRules base-branch settings.
- Bot-PR handling elsewhere (skipping bot-created PRs, the
! deps → next labelling, feature-pr.yml) assumes Dependabot branch and author names.
- The
dependabot.yml template and the v4-bootstrap onboarding step need Renovate equivalents, and the repo-onboarding docs need updating.
- Existing Dependabot configs and open Dependabot PRs need a cutover plan per repo.
Open questions
- Hosted Mend app versus a self-hosted Renovate run in our own workflows (the hosted free tier's four-hour cycle and single job may matter at fleet size).
- How Renovate's vulnerability PRs relate to GitHub Dependabot alerts and security updates, and whether to keep Dependabot security updates enabled alongside Renovate.
- Whether the bot identity needs to be the existing
cldmv-bot app for signing and auto-merge, or whether Renovate's own identity is acceptable.
Out of scope for now
Not being started yet. The fix-headers and @cldmv/configs fleet rollout comes first. Until then, the per-repo dependabot.yml ignore stays as is.
Problem
Dependabot has no shared configuration: no
extends, no org-widedependabot.yml. Every repo carries its own copy of.github/dependabot.yml, seeded from thedependabot.ymltemplate. A policy that should apply everywhere has to be swept into each repo and then drifts.The case that surfaced this: TypeScript 7.0 breaks coverage measurement, so every repo needs to ignore 7.0.x while still accepting 7.1, which is planned to fix it (wisp#21 carries the ignore for wisp today). Most other org configuration is centrally controlled with per-repo overrides, and dependency policy is the exception.
Proposal
Move dependency updates to Renovate. The hosted Mend Renovate GitHub app is free for public and private repositories (free tier: one concurrent job on a four-hour cycle), and self-hosting is also free.
renovate.jsonordefault.json, consumed asgithub>CLDMV/.github) holds the org policy: schedule,target-branch(next), commit prefix, labels, the vitest-family grouping, and package rules such as the TypeScript 7.0.x ignore.renovate.jsonis{"extends": ["github>CLDMV/.github"]}plus only its own overrides.What changes in the v4 flow
The flow is built around Dependabot, so this is a migration, not a config swap:
dependabot-auto-mergeand its action key off Dependabot's actor and metadata.dependabot-recreateuses Dependabot's@dependabot recreatecommand.hotfixes(redirect-hotfix-pr, described in release-flow-v4.md) detects a Dependabot PR whose base differs from the configured routinetarget-branch. Renovate needs an equivalent: vulnerability-alert PRs routed tohotfixesthroughvulnerabilityAlertsandpackageRulesbase-branch settings.! deps → nextlabelling,feature-pr.yml) assumes Dependabot branch and author names.dependabot.ymltemplate and thev4-bootstraponboarding step need Renovate equivalents, and the repo-onboarding docs need updating.Open questions
cldmv-botapp for signing and auto-merge, or whether Renovate's own identity is acceptable.Out of scope for now
Not being started yet. The fix-headers and
@cldmv/configsfleet rollout comes first. Until then, the per-repodependabot.ymlignore stays as is.