vocabulary: name: Renovate Vocabulary description: >- Vocabulary and taxonomy for Renovate, the Open Source cross-platform dependency automation tool. Covers configuration concepts, update strategies, package manager support, platform integrations, and workflow patterns. version: "1.0" created: "2026-05-02" modified: "2026-05-02" tags: - Automation - Dependency Management - CI/CD - Open Source terms: # Core Concepts - term: Dependency Update definition: >- An automated pull request created by Renovate that bumps one or more dependency versions in a repository's package manifest files and lock files. category: Core tags: [Automation, Dependencies] - term: Package Manager definition: >- A language ecosystem tool that manages software dependencies (e.g., npm for JavaScript, pip for Python, Maven for Java). Renovate supports 90+ package managers across all major programming languages. category: Core tags: [Dependencies, Ecosystem] - term: Lock File definition: >- A file that records the exact resolved versions of all transitive dependencies (e.g., package-lock.json, yarn.lock, Pipfile.lock). Renovate updates lock files alongside manifest files for consistency. category: Core tags: [Dependencies, Reproducibility] # Update Types - term: Major Update definition: >- A semver major version bump (e.g., 1.x.x to 2.x.x) that may include breaking changes. Renovate creates separate PRs for major updates and allows them to be reviewed independently. category: Update Type tags: [Semver, Breaking Changes] - term: Minor Update definition: >- A semver minor version bump (e.g., 1.2.x to 1.3.x) adding new features without breaking backward compatibility. category: Update Type tags: [Semver, Features] - term: Patch Update definition: >- A semver patch version bump (e.g., 1.2.3 to 1.2.4) containing only bug fixes and security patches, no feature changes. category: Update Type tags: [Semver, Bug Fixes] - term: Pin definition: >- Converting a floating version range (e.g., ^1.2.0) to an exact pinned version (e.g., 1.2.3) for reproducible builds. Renovate can auto-pin dependencies on initial setup. category: Update Type tags: [Semver, Reproducibility] - term: Digest Pin definition: >- Replacing a Docker image tag with an immutable SHA256 digest for guaranteed reproducibility in container-based builds. category: Update Type tags: [Docker, Reproducibility] # Configuration - term: Preset definition: >- A shareable, reusable Renovate configuration bundle. Built-in presets like config:recommended provide sensible defaults. Custom presets can be published to npm or GitHub for team-wide sharing. category: Configuration tags: [Configuration, Sharing] - term: Package Rule definition: >- A conditional configuration block that applies settings to specific packages or groups matched by name, pattern, manager, or update type. Used for custom automerge, grouping, scheduling, and disabling rules. category: Configuration tags: [Configuration, Rules] - term: Group definition: >- A Renovate feature that combines updates for multiple related packages into a single pull request, reducing PR noise (e.g., grouping all ESLint packages or all AWS SDK packages). category: Configuration tags: [Configuration, PRs] # Platform Features - term: Dependency Dashboard definition: >- A GitHub/GitLab issue automatically maintained by Renovate listing all pending dependency updates with their status. Allows maintainers to approve, reject, or defer specific updates from one central location. category: Features tags: [GitHub, Visibility] - term: Merge Confidence definition: >- A Renovate data feed scoring the historical merge success rate of specific version bumps across many repositories. Helps assess whether an update is safe to automerge. category: Features tags: [Analytics, Automation] - term: Automerge definition: >- Automatically merging pull requests that pass all required CI checks. Can be configured globally or per-package rule, typically for low-risk patch updates of well-tested dependencies. category: Features tags: [Automation, CI/CD] # Self-Hosting - term: Self-Hosted Renovate definition: >- Running Renovate on your own infrastructure via the npm package, Docker container, GitHub Action, or Kubernetes deployment. Gives full control over scheduling, secrets, and configuration. category: Deployment tags: [Infrastructure, Self-Hosted] - term: Mend Renovate App definition: >- The hosted cloud version of Renovate operated by Mend.io as a GitHub/GitLab app. No infrastructure required; install the app and Renovate runs automatically. category: Deployment tags: [Cloud, SaaS] # Security - term: Vulnerability Alert definition: >- A Renovate PR triggered by a security advisory (CVE) for a currently installed dependency version. Created immediately regardless of the regular update schedule. category: Security tags: [Security, CVE]