World Congress 2026 Europe Jul 10, 2026 Session details

Automate or Stagnate: Keep Your Dependencies up to date with Renovate

Susanne Bach Ladefoged Hou

Delaying updates increases subsequent upgrade time by 60% per missed major version. Escape dependency hell and learn to safely automate your pipelines with Renovate.

Pause
Mute Enter Fullscreen
#1 about 5 min

Why prioritizing continuous software dependency management matters

The challenges of managing dependencies across thousands of repositories and how regular updates reduce compounding technical debt.

#2 about 2 min

Understanding package managers and complex dependency graphs

How package managers handle nested libraries and the risks hiding deep within the dependency tree.

#3 about 2 min

Choosing tools for automated software dependency management

Evaluating automation tools like Dependabot and Renovate based on organizational needs and multiplatform support capabilities.

#4 about 2 min

Crucial considerations before automating software dependency updates

Why defining pull request ownership and iterating on configurations is critical for establishing successful automation workflows.

#5 about 4 min

Executing phased rollout strategies for dependency updates

How to safely scale automation across organizations by phasing rollouts via specific dependency subsets or canary repositories.

#6 about 2 min

Gating automated updates by semantic versioning risks

Limiting automated updates to patch versions or known vulnerabilities to minimize the risk of introducing breaking changes.

#7 about 3 min

Augmenting dependency management workflows with artificial intelligence

Leveraging AI agents to automatically fix broken tests, interpret changelogs, and proactively scan for suspicious dependency releases.

#8 about 2 min

Identifying scenarios where dependency automation becomes impractical

Recognizing environments with heavy compliance, insufficient test coverage, or legacy systems that hinder automated dependency updates.

#9 about 2 min

Controlling pull request volume to prevent developer fatigue

Strategies for capping open pull requests, widening groupings, and scheduling updates to avoid overwhelming engineering teams.

#10 about 1 min

Structuring and separating configuration files for scale

How separating package rule configurations by concern improves readability and debugging across large organizational implementations.

#11 about 3 min

Managing faulty packages with automated rollback pull requests

Using specific configuration rules to automatically revert broken dependencies when runtime bugs are discovered across multiple repositories.

#12 about 3 min

Reviewing real-world configurations and handling untested repositories

Finding configuration inspiration from open-source projects and using canary repositories to test software updates in untested environments.

Matching moments

1:17 min

Automating package dependency updates with scanning algorithms

Dennis Doomen Dennis Doomen · World Congress 2025

1:41 min

Elevating developer workflows by automating repetitive foundational tasks

2:49 min

Managing dependency vulnerabilities and transitive software risks

Niels Tanis Niels Tanis · World Congress 2024

2:22 min

Automating library updates and vulnerability alerts with Dependabot

Kevin Lewis Kevin Lewis · World Congress 2025

1:34 min

Refactoring bloated legacy outputs and managing aggressive dependency creep

Sergej Reznik Sergej Reznik · Europe 2026 Virtual

1:00 min

Encouraging broader team adoption of security automation practices

Ramona Schwering Ramona Schwering · World Congress 2024

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Still on 4.8 or lower? A Practical Guide to Moving Your "Un-Migratable" .NET Apps

Isaac Levin

Developer Advocate

Isaac Levin
Open session

World Congress 2026 North America

Merging at Scale: From Broken Builds to Green Mainline

Manjari Akella, Preetam Dwivedi

Manjari Akella
Preetam Dwivedi
Open session

World Congress 2026 North America

Agentic Drift: keeping pace with your agents

John Coghlan

Senior Director, Developer Advocacy at GitLab

John Coghlan
Open session

World Congress 2026 North America

The Broken Rung: How AI is Rebuilding Software Development from the Ground Up

Tomislav Tipurić

Chief Technology Officer, Nephos

Tomislav Tipurić
Open session

World Congress 2026 North America

When Humans Stop Writing Code: Rethinking Languages, Compilers, and Responsibility

Simon Auer

Organizer of flutter vienna meetup and CEO of marqably

Simon Auer
Open session

World Congress 2026 North America

AI vs. AI: Defending the open source supply chain with agentic workflows

Manfred Moser

Senior Principal DevRel Engineer at Chainguard

Manfred Moser