OSS Support Hub / Developer Tools

Node.js Developer Tools AGPL-3.0 Latest: 43.180.0

Renovate

Automated dependency update tool — keeps your dependencies up-to-date across all ecosystems

Project Health at a Glance

Live data from GitHub and npm, updated daily.

21.5K
GitHub Stars
📦
43.180.0
Latest Release · Yesterday
🔄
0d
Avg. Release Cadence
🐛
1.1K
Open Issues
📅
Today
Last Commit
⬇️
458.1K
Weekly Downloads
🔒
10
Active CVEs

Data last fetched: 2026-05-15

Known Vulnerabilities

10 active CVEs reported via OSV.dev

Renovate vulnerable to arbitrary command injection via hermit manager and maliciously named dependencies

Published: 2026-01-13 Fixed in: 40.33.0

Renovate vulnerable to Azure DevOps token leakage in logs

Published: 2020-09-14 Fixed in: 23.25.1

Renovate vulnerable to arbitrary command injection via helmv3 manager and malicious Chart.yaml file

Published: 2026-01-13 Fixed in: 40.33.0

Renovate affected by remote code execution was possible using the bazel-module or bazelisk managers, when using lockFileMaintenance

Published: 2026-04-16 Fixed in: 43.102.11

Child processes spawned by Renovate incorrectly have full access to environment variables

Published: 2026-02-13 Fixed in: 42.96.3

Renovate vulnerable to arbitrary command injection via npm manager and malicious Renovate configuration

Published: 2026-01-13 Fixed in: 40.33.0

Renovate vulnerable to arbitrary command injection via Gradle Wrapper and malicious `distributionUrl`

Published: 2026-01-13 Fixed in: 42.68.5

Renovate vulnerable to arbitrary command injection via helmv3 manager and registryAliases

Published: 2024-04-23 Fixed in: 37.199.0

Renovate vulnerable to leakage of temporary repository tokens into Pull Request comments

Published: 2019-10-21 Fixed in: 19.38.7

Renovate vulnerable to arbitrary command injection via gleam manager and malicious gleam.toml file

Published: 2026-01-13 Fixed in: 40.33.0

Alternatives to Renovate

Other Developer Tools projects in the Node.js ecosystem worth evaluating.

Support Options for Renovate

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Renovate — without relying on volunteer maintainers.

Talk to an Expert →