💻 Coding

Dependabot to Renovate Migration Plan with a Ready renovate.json

Migrate a repo from .github/dependabot.yml to Renovate: map every ecosystem, schedule, group, and ignore rule to packageRules, write a validated renovate.json, and plan the cutover so you never get duplicate PRs.

0.0
0Reviews
P
October 5, 2026

Prompt

Act as a platform engineer who has migrated many repositories from GitHub Dependabot version updates to Renovate. You translate config field by field, explain each Renovate option you use, and plan a cutover with no duplicate update PRs.

Inputs:
- Current .github/dependabot.yml pasted in full: [DependabotYml]
- Package managers and lockfiles in the repo (npm, pnpm, pip, poetry, docker, github-actions, terraform): [Ecosystems]
- Merge policy (who may automerge what, required checks, branch protection): [MergePolicy]
- Team timezone and quiet hours: [Timezone]
- How Renovate runs (Mend Renovate GitHub App, self-hosted renovate CLI, or GitLab runner) and its version if known: [RenovateRuntime]
- Packages that must never jump a major version: [PinnedMajors]
- Output format: [Format]

Generate:
1. Field map. A table that takes every key in DependabotYml (package-ecosystem, directory, schedule.interval, open-pull-requests-limit, groups with patterns, ignore with update-types, labels, reviewers, commit-message prefix) and names the Renovate equivalent (manager auto-detection or enabledManagers, schedule plus timezone, prConcurrentLimit, packageRules with groupName and matchPackageNames, matchUpdateTypes with enabled false, labels, reviewers or CODEOWNERS, semanticCommits or commitMessagePrefix). Mark anything with no equivalent.
2. renovate.json. Start with $schema and extends config:recommended. Add timezone and schedule in Renovate's natural-language syntax, prConcurrentLimit, minimumReleaseAge for third-party packages, lockFileMaintenance, and packageRules for groups, automerge per MergePolicy, and PinnedMajors. If RenovateRuntime is version 38 or newer, use glob or regex patterns inside matchPackageNames instead of the deprecated matchPackagePatterns.
3. GitHub Actions handling. If Ecosystems includes github-actions, decide whether to add helpers:pinGitHubActionDigests and explain the trade-off.
4. Security updates. Explain that Dependabot security alerts are separate from version updates, and set vulnerabilityAlerts labels and schedule override so security PRs are not held by the weekly schedule.
5. Cutover runbook. Ordered steps: validate with renovate-config-validator, merge the Renovate onboarding PR, check the Dependency Dashboard issue, delete .github/dependabot.yml in the same week, close stale Dependabot PRs, and the rollback step.
6. Open questions. Only items that DependabotYml or MergePolicy leave ambiguous.

Constraints:
- Valid JSON only in the config block, no comments inside it.
- Do not invent repo paths, package names, or reviewers that Inputs did not give.
- Never enable automerge for major updates unless MergePolicy says so.
- No em dashes.

Instructions

Replace every [bracket] with your details before running. Works on ChatGPT, Claude, and Gemini.

Generated Output

This image was generated using the prompt above.

Dependabot to Renovate Migration Plan with a Ready renovate.json - Result

Examples

Example Input

DependabotYml: version 2; updates: npm in / weekly on monday, open-pull-requests-limit 10, groups aws-sdk patterns '@aws-sdk/*', ignore dependency-name 'react' update-types version-update:semver-major; docker in /deploy weekly; github-actions in / monthly; labels ['deps']
Ecosystems: npm with package-lock.json, Dockerfile in deploy/, GitHub Actions workflows
MergePolicy: devDependencies patch and minor may automerge after CI passes; everything else needs one review
Timezone: America/Chicago, no PRs during business hours
RenovateRuntime: Mend Renovate GitHub App (hosted, current)
PinnedMajors: react, react-dom
Format: table, JSON, runbook

Example Output

1. Field map
| Dependabot | Renovate |
| package-ecosystem npm, docker, github-actions | auto-detected managers npm, dockerfile, github-actions (no config needed) |
| directory / and /deploy | auto-detected; Renovate scans the whole repo |
| schedule weekly monday / monthly | schedule plus timezone; monthly via a packageRule for github-actions |
| open-pull-requests-limit 10 | prConcurrentLimit 10 |
| groups aws-sdk '@aws-sdk/*' | packageRules groupName aws-sdk, matchPackageNames ['@aws-sdk/**'] |
| ignore react semver-major | packageRules matchPackageNames react, react-dom, matchUpdateTypes major, enabled false |
| labels ['deps'] | labels ['deps'] |

2. renovate.json
{
  "$schema": "https://docs.renovatebot.com/renovate-schema.json",
  "extends": ["config:recommended"],
  "timezone": "America/Chicago",
  "schedule": ["after 6pm on monday", "before 7am on tuesday"],
  "prConcurrentLimit": 10,
  "labels": ["deps"],
  "minimumReleaseAge": "3 days",
  "lockFileMaintenance": { "enabled": true },
  "vulnerabilityAlerts": { "labels": ["deps", "security"], "schedule": ["at any time"] },
  "packageRules": [
    { "groupName": "aws-sdk", "matchPackageNames": ["@aws-sdk/**"] },
    { "matchPackageNames": ["react", "react-dom"], "matchUpdateTypes": ["major"], "enabled": false },
    { "matchDepTypes": ["devDependencies"], "matchUpdateTypes": ["minor", "patch"], "automerge": true },
    { "matchManagers": ["github-actions"], "schedule": ["before 7am on the first day of the month"] }
  ]
}

Notes: the schedule window covers Monday evening to Tuesday morning Chicago time, so nothing opens during business hours. minimumReleaseAge holds brand-new releases for 3 days. Automerge applies only to devDependencies minor and patch, and still waits for required checks.

3. GitHub Actions
Optional: add helpers:pinGitHubActionDigests to extends. Pros: pinned SHAs resist tag hijacking. Cons: every action bump becomes a digest PR. Recommend yes, since Actions run monthly anyway.

4. Security updates
Dependabot alerts in the Security tab keep working; only version updates move to Renovate. vulnerabilityAlerts uses schedule 'at any time' so a fix does not wait for Monday.

5. Cutover runbook
1) Open a branch with renovate.json and run: npx --yes --package renovate -- renovate-config-validator
2) Install or confirm the Mend Renovate app on this repo and merge its onboarding PR (or merge your branch if onboarding is already done).
3) Open the Dependency Dashboard issue and confirm npm, dockerfile, and github-actions dependencies are listed.
4) Same day, delete .github/dependabot.yml so both bots do not open the same bump.
5) Close open Dependabot PRs with a comment pointing to the Dashboard.
Rollback: restore dependabot.yml from git history and set "enabled": false at the top of renovate.json.

6. Open questions
- Should docker base image digests be pinned too (pinDigests for dockerfile)?
- Does the deps label need to stay single, or can security PRs carry a second label?

Reviews (0)

Please login to leave a review.
Loading reviews...