Back to Discover

#dependabot migration

1 prompt found

Dependabot to Renovate Migration Plan with a Ready renovate.json
๐Ÿ’ป Coding

Dependabot to Renovate Migration Plan with a Ready renovate.json

PpromptstudioยทOct 5, 2026
No rating

Migrate a repo from .github/dependabot.yml to Renovate: map every ecosystem, schedule, group, and ignore rule to packageRules, write a validated renovate.json, and plan the cutover so you never get duplicate PRs.

Act as a platform engineer who has migrated many repositories from GitHub Dependabot version updates to Renovate. You translate config field by field, explain each Renovate option you use, and plan a cutover with no duplicate update PRs. Inputs: - Current .github/dependabot.yml pasted in full: [DependabotYml] - Package managers and lockfiles in the repo (npm, pnpm, pip, poetry, docker, github-actions, terraform): [Ecosystems] - Merge policy (who may automerge what, required checks, branch protection): [MergePolicy] - Team timezone and quiet hours: [Timezone] - How Renovate runs (Mend Renovate GitHub App, self-hosted renovate CLI, or GitLab runner) and its version if known: [RenovateRuntime] - Packages that must never jump a major version: [PinnedMajors] - Output format: [Format] Generate: 1. Field map. A table that takes every key in DependabotYml (package-ecosystem, directory, schedule.interval, open-pull-requests-limit, groups with patterns, ignore with update-types, labels, reviewers, commit-message prefix) and names the Renovate equivalent (manager auto-detection or enabledManagers, schedule plus timezone, prConcurrentLimit, packageRules with groupName and matchPackageNames, matchUpdateTypes with enabled false, labels, reviewers or CODEOWNERS, semanticCommits or commitMessagePrefix). Mark anything with no equivalent. 2. renovate.json. Start with $schema and extends config:recommended. Add timezone and schedule in Renovate's natural-language syntax, prConcurrentLimit, minimumReleaseAge for third-party packages, lockFileMaintenance, and packageRules for groups, automerge per MergePolicy, and PinnedMajors. If RenovateRuntime is version 38 or newer, use glob or regex patterns inside matchPackageNames instead of the deprecated matchPackagePatterns. 3. GitHub Actions handling. If Ecosystems includes github-actions, decide whether to add helpers:pinGitHubActionDigests and explain the trade-off. 4. Security updates. Explain that Dependabot security alerts are separate from version updates, and set vulnerabilityAlerts labels and schedule override so security PRs are not held by the weekly schedule. 5. Cutover runbook. Ordered steps: validate with renovate-config-validator, merge the Renovate onboarding PR, check the Dependency Dashboard issue, delete .github/dependabot.yml in the same week, close stale Dependabot PRs, and the rollback step. 6. Open questions. Only items that DependabotYml or MergePolicy leave ambiguous. Constraints: - Valid JSON only in the config block, no comments inside it. - Do not invent repo paths, package names, or reviewers that Inputs did not give. - Never enable automerge for major updates unless MergePolicy says so. - No em dashes.