pinup has opinions: twelve decisions and their price
pinup reads Renovate's configuration. In twelve places it holds a firm opinion, mostly a different one from Renovate's. Not on principle, but because in my estate each of those places once cost time or money.
This series explains the decisions one by one. Each part names the opinion, the alternative, the price and the occasion. One part every Monday, until just before New Year.
01 — Opinions instead of options
A tool for dependency updates has to leave a lot open. Renovate serves thousands of setups, and that only works with options. pinup serves one to begin with: my own estate of around 200 repositories. There, a few questions came up so often that I no longer wanted them as an option, but as a rule.
An opinion in code costs more than an option. It rules setups out, and it has to justify itself. That is why every part has the same shape:
- The opinion in one sentence.
- The alternative, and why it is right elsewhere.
- The price: what pinup cannot do because of it.
- The occasion: a measured incident, not a theory.
- The enforcement: a type, a test or a gate. Not discipline.
02 — Renovate remains a great tool
First things first, because otherwise the series gets misread. I used Renovate gladly for years. It still runs at some of my clients, and there I keep recommending it.
Where pinup decides differently, Renovate's decision is usually the right one for its context. A tool for everyone has to be tolerant. A tool for one estate may be strict. That is a judgement about fit, not about quality.
pinup's own configuration is called .pinup.yaml or .pinup.jsonc (also .yml or .json). pinup still reads an existing renovate.json, as well as renovate.json5, .renovaterc and .renovaterc.json in the repository root. The reason: a switch should change no byte in any repository. Whoever switches renames nothing first, and whoever switches back does not either. pinup does not read a configuration under .github/ or .gitlab/, though; that has to move once. pinup refuses only two configuration files at once, instead of silently picking one.
For the same reason, branch names and # renovate: annotations stay the same. That gets a part of its own.
03 — The twelve opinions at a glance
| Date | Opinion | What it is about |
|---|---|---|
| 12 Oct 2026 | Nothing happens without a reason | Every held update names its reason, its rule and its time. |
| 19 Oct 2026 | A gate that was never red is no gate | Mutation tests for the checks. |
| 26 Oct 2026 | Untracked is not a gap | What nothing updates, and what may stay that way. |
| 2 Nov 2026 | The core decides, plugins apply | Plugins get no credentials and only their share of the checkout. |
| 9 Nov 2026 | Compatible where it protects users | Configuration, branch names and annotations stay Renovate's. |
| 16 Nov 2026 | The stricter label wins | The measured change counts, not only the version number. |
| 23 Nov 2026 | No byte without a plan | Every run writes a machine-readable plan first. |
| 30 Nov 2026 | Bytes, not trees | A change is a byte range. YAML and JSON are never re-serialised. |
| 7 Dec 2026 | Configuration with provenance | Every value knows which source set it. |
| 14 Dec 2026 | Boring dependencies | Two direct third-party libraries. GPG deliberately not rebuilt. |
| 21 Dec 2026 | The tool updates itself | Dogfooding as the criterion for every release. |
| 28 Dec 2026 | Withdrawn is not deleted | Vulnerable versions of my own leave circulation automatically, without being deleted. |
The dates hold as long as nothing more urgent comes up. A CVE wave takes precedence here. The links work from each date on.
Terms that recur
- Estate: the roughly 200 repositories I run and pinup updates.
- Runner: the repository with the scheduled CI job that runs pinup across all repositories. It also holds the central configuration every other one extends.
- Shadow mode: before the switch, pinup ran next to Renovate. It wrote nothing and compared its plans with Renovate's merge requests.
- Fast lane: a targeted run as soon as one of my own packages has a release. It goes only to the repositories that use the package.
- Golden tests: tests that compare the result of a run with a checked, stored expectation. The expectation is never rewritten automatically.
- Wolfi: a Linux distribution for container images. From it I build the packages for my own images.
Frequently asked questions
Is the series a reckoning with Renovate?+
No. Renovate is the reference pinup is measured against, and at some clients it remains my recommendation. Every part names the alternative and explains why it is right in other setups. The series describes a different fit, not a better tool.
Do I need pinup to get something out of it?+
No. Most of the decisions carry over to any tool, including your own Renovate configuration. A held update without a reason is a bug, whichever tool holds it. A gate that was never red checks nothing, whichever pipeline it sits in.
Where do I find pinup?+
Code, releases and documentation are on GitHub, under Apache-2.0. The project page has a quickstart and the chapters on configuration, the plan and security.
Conclusion
Twelve decisions, twelve prices. The series starts on 12 October with the opinion that made pinup necessary in the first place: nothing happens without a reason.
The occasion for pinup is told in the post on the switch. Code and documentation are on GitHub, an overview on the pinup project page.
Which of these decisions matter for your setup? I will look at your configuration.
A look at your Renovate or pinup configuration with pinup advise: what it does not read, what it says twice and which updates silently stay behind.
About the author

Kai Ole Hartwig
Programming since 2002 – self-taught, set up my own business with KO-Web in 2012. Over 100 projects, with a focus on security, performance, automation and quality. Today freelance: DevSecOps consulting, training and software development.
