Kai Ole Hartwig
5 min read
Low
By

pinup has opinions: twelve decisions and their price

pinup reads Renovate's configuration. In twelve places it holds a firm opinion, mostly a different one from Renovate's. Not on principle, but because in my estate each of those places once cost time or money.

This series explains the decisions one by one. Each part names the opinion, the alternative, the price and the occasion. One part every Monday, until just before New Year.

01 — Opinions instead of options

A tool for dependency updates has to leave a lot open. Renovate serves thousands of setups, and that only works with options. pinup serves one to begin with: my own estate of around 200 repositories. There, a few questions came up so often that I no longer wanted them as an option, but as a rule.

An opinion in code costs more than an option. It rules setups out, and it has to justify itself. That is why every part has the same shape:

02 — Renovate remains a great tool

First things first, because otherwise the series gets misread. I used Renovate gladly for years. It still runs at some of my clients, and there I keep recommending it.

Where pinup decides differently, Renovate's decision is usually the right one for its context. A tool for everyone has to be tolerant. A tool for one estate may be strict. That is a judgement about fit, not about quality.

pinup's own configuration is called .pinup.yaml or .pinup.jsonc (also .yml or .json). pinup still reads an existing renovate.json, as well as renovate.json5, .renovaterc and .renovaterc.json in the repository root. The reason: a switch should change no byte in any repository. Whoever switches renames nothing first, and whoever switches back does not either. pinup does not read a configuration under .github/ or .gitlab/, though; that has to move once. pinup refuses only two configuration files at once, instead of silently picking one.

For the same reason, branch names and # renovate: annotations stay the same. That gets a part of its own.

03 — The twelve opinions at a glance

DateOpinionWhat it is about
12 Oct 2026Nothing happens without a reasonEvery held update names its reason, its rule and its time.
19 Oct 2026A gate that was never red is no gateMutation tests for the checks.
26 Oct 2026Untracked is not a gapWhat nothing updates, and what may stay that way.
2 Nov 2026The core decides, plugins applyPlugins get no credentials and only their share of the checkout.
9 Nov 2026Compatible where it protects usersConfiguration, branch names and annotations stay Renovate's.
16 Nov 2026The stricter label winsThe measured change counts, not only the version number.
23 Nov 2026No byte without a planEvery run writes a machine-readable plan first.
30 Nov 2026Bytes, not treesA change is a byte range. YAML and JSON are never re-serialised.
7 Dec 2026Configuration with provenanceEvery value knows which source set it.
14 Dec 2026Boring dependenciesTwo direct third-party libraries. GPG deliberately not rebuilt.
21 Dec 2026The tool updates itselfDogfooding as the criterion for every release.
28 Dec 2026Withdrawn is not deletedVulnerable versions of my own leave circulation automatically, without being deleted.

The dates hold as long as nothing more urgent comes up. A CVE wave takes precedence here. The links work from each date on.

Terms that recur

Frequently asked questions

Is the series a reckoning with Renovate?+

No. Renovate is the reference pinup is measured against, and at some clients it remains my recommendation. Every part names the alternative and explains why it is right in other setups. The series describes a different fit, not a better tool.

Do I need pinup to get something out of it?+

No. Most of the decisions carry over to any tool, including your own Renovate configuration. A held update without a reason is a bug, whichever tool holds it. A gate that was never red checks nothing, whichever pipeline it sits in.

Where do I find pinup?+

Code, releases and documentation are on GitHub, under Apache-2.0. The project page has a quickstart and the chapters on configuration, the plan and security.

Conclusion

Twelve decisions, twelve prices. The series starts on 12 October with the opinion that made pinup necessary in the first place: nothing happens without a reason.

The occasion for pinup is told in the post on the switch. Code and documentation are on GitHub, an overview on the pinup project page.

Which of these decisions matter for your setup? I will look at your configuration.

A look at your Renovate or pinup configuration with pinup advise: what it does not read, what it says twice and which updates silently stay behind.

Book a call →

About the author

Photo of Kai Ole Hartwig.

Kai Ole Hartwig

Freelance DevSecOps consultant · OnlyOle Consulting

Programming since 2002 – self-taught, set up my own business with KO-Web in 2012. Over 100 projects, with a focus on security, performance, automation and quality. Today freelance: DevSecOps consulting, training and software development.