reversible Your old config is left in place until you delete it

migrating

Bring the config you already wrote

Nobody wants to re-derive two years of package rules from memory. buddy setup detects a Renovate or Dependabot configuration, converts the parts that have an equivalent, and tells you plainly about the parts that do not.

$ buddy setup

             __
    (\,------'()'--o    found renovate.json
     (_    ___    /~"   migrating configuration
      (_)_)  (_)_)

  schedule       "before 4am on monday"
                 → weekly preset
  packageRules   6 rules
                 → 4 groups, 2 ignores
  automerge      patch only
                 → autoMerge.conditions
  assignees      2 → pullRequest.assignees
  labels         1 → pullRequest.labels

  no equivalent (2)
    · rangeStrategy: "bump"
      buddy preserves the existing
      constraint operator instead
    · osvVulnerabilityAlerts
      advisories are always on

  write buddy.config.ts? (y/N)
🔎

Reads both, automatically

renovate.json, .renovaterc, a renovate block in package.json, and .github/dependabot.yml or .yaml. Detection happens as part of setup — there is no separate migrate command to remember.

📋

Reports what does not map

The migration report lists every setting that has no Buddy equivalent and why. A migration that quietly drops a rule is worse than one that refuses to run, because you find out six weeks later when something you thought was pinned moved.

🎨

Package rules become groups

Match patterns become group patterns, per-rule update types become per-group strategies, and enabled: false becomes an ignore entry.

📅

Schedules become presets

A Renovate schedule string or a Dependabot interval maps to a workflow preset — standard, high-frequency, security, minimal — and you can hand-edit the generated cron afterwards.

👥

Reviewers and labels carry over

assignees, reviewers and labels move straight into pullRequest, so the routing your team relies on keeps working from the first run.

🤝

Run both for a fortnight

Nothing forces a cut-over. Point Buddy at a different label and branch prefix, let both open pull requests for a sprint, and turn the old one off when you are convinced.

The migration, step by step

bun add -g @buddysh/buddy
buddy setup
  1. Detection. Buddy looks for Renovate and Dependabot configuration in the usual places.
  2. Conversion. Schedules, package rules, ignores, automerge policy, assignees, reviewers and labels are mapped.
  3. Report. You get a summary of what carried over, at what confidence, and what has no equivalent — before anything is written.
  4. Write. buddy.config.ts and the workflows are generated only after you say yes.

What is deliberately different

A few Renovate behaviours have no Buddy equivalent because Buddy takes a different position, not because it is missing:

RenovateBuddy
rangeStrategy: bump / pin / replaceThe existing constraint operator is preserved. =2.28 becomes =2.31, never ==2.31 — replacing a deliberately flexible constraint with a pin is a change nobody asked for arriving inside a dependency update.
osvVulnerabilityAlertsAdvisories are always on. There is no version of this that you want off.
Hosted schedulingA cron in a workflow you own, so the schedule is visible in the repository rather than in a vendor dashboard.
dependencyDashboardApprovalThe dashboard's checkboxes trigger a rebase; approval flows through your normal review, not a second one.

Your renovate.json is not deleted. Turn the old bot off when you are ready, and delete the file whenever you like.

Then take the half Renovate never had

Once the dependency loop is running, the reviewer is already installed:

buddy review                # local, before the PR exists
buddy security              # audit your workflows
buddy gate 128              # publish the pre-merge check run

From Renovate · From Dependabot · Buddy vs Renovate · Buddy vs Dependabot · The setup command