# Using Renovate with Chainguard Containers

URL: https://deploy-preview-4124--ornate-narwhal-088216.netlify.app/chainguard/containers/security-and-compliance/updating-containers/renovate.md
Last Modified: September 28, 2026
Tags: Chainguard Containers

How to use Renovate to automatically keep Chainguard Containers, Helm charts and packages updated

Renovate can be used to alert on updates to Chainguard Containers, Helm charts and APK packages. This can be an effective way to keep your images up-to-date and free of CVEs. This article explains how to configure Renovate for each.
Prerequisites To follow this guide, you need:
Renovate installed and configured. Refer to Renovate&rsquo;s installation instructions if you haven&rsquo;t set this up. chainctl, Chainguard&rsquo;s command-line interface, installed on your local machine. Several examples in this guide use it. Refer to How to install chainctl if you haven&rsquo;t set this up. Set up credentials for Renovate In order to support versioned images from a private repository, you must provide Renovate with credentials to access the Chainguard registry at cgr.dev. You can do this by creating a token with chainctl, as in this example:
chainctl auth configure-docker --pull-tokenThis command responds with output such as:
To use this pull token in another environment, run this command: docker login &#34;cgr.dev&#34; --username &#34;&lt;identity-id&gt;&#34; --password &#34;&lt;pull-token&gt;&#34;By default, this credential is good for 30 days.
You can now configure hostRules in Renovate to support the Chainguard registry. Depending on how Renovate was set up, you can add this to your Renovate configuration with a setting such as:
{ ... &#34;hostRules&#34;: [ { &#34;hostType&#34;: &#34;docker&#34;, &#34;matchHost&#34;: &#34;cgr.dev&#34;, &#34;username&#34;: &#34;&lt;identity-id&gt;&#34;, &#34;password&#34;: &#34;&lt;pull-token&gt;&#34; }] }Be aware that you SHOULD NOT check this file into source control with the exposed secret. Instead, you can use environment variables that you pass in at runtime if you use a config.js file:
module.exports = { ... &#34;hostRules&#34;: [ { &#34;hostType&#34;: &#34;docker&#34;, &#34;matchHost&#34;: &#34;cgr.dev&#34;, &#34;username&#34;: process.env.CGR_USERNAME, &#34;password&#34;: process.env.CGR_PASSWORD, }] };But an even more secure solution would be to create a script that automatically updates the configuration with the correct values by calling chainctl. If you do this, you should also set the credential lifetime to a much shorter period with the --ttl flag:
chainctl auth configure-docker --pull-token --ttl 10mThis sets the pull token&rsquo;s lifetime to 10 minutes, which limits the risk posed if the token leaks. You can also set the lifetime to a longer period for more manual configurations.
Update versioned container images By default, Renovate will now open pull requests for any out-of-date versions of images it finds. For example, you can run Renovate by pushing the following Dockerfile to a repository overseen by Renovate:
FROM cgr.dev/chainguard.edu/python:3.11-dev AS builder ... FROM cgr.dev/chainguard.edu/python:3.11 ...At the time of writing, version 3.12 was the current version of the Python image, so Renovate opened a pull request to update the reference.
Not all images use semantic versioning. Refer to the Renovate documentation for details on how to support different schemes.
Ideally, image references should also be pinned to a digest, as shown in the following section.
Update :latest container images Renovate also supports updating image references that are pinned to digests. This lets you keep mutable tags such as :latest in sync with the most up-to-date version.
As an example, the following Dockerfile prompts Renovate to open two similar pull requests:
FROM cgr.dev/chainguard/go:latest-dev@sha256:ff187ecd4bb5b45b65d680550eed302545e69ec4ed45f276f385e1b4ff0c6231 AS builder WORKDIR /work COPY go.mod /work/ COPY cmd /work/cmd COPY internal /work/internal RUN CGO_ENABLED=0 go build -o hello ./cmd/server FROM cgr.dev/chainguard/static:latest@sha256:5e9c88174a28c259c349f308dd661a6ec61ed5f8c72ecfaefb46cceb811b55a1 COPY --from=builder /work/hello /hello ENTRYPOINT [&#34;/hello&#34;] Pin digests The pinDigests option configures Renovate to add digests to image references that don&rsquo;t contain them.
The following example Renovate configuration includes this option:
{ &#34;$schema&#34;: &#34;https://docs.renovatebot.com/renovate-schema.json&#34;, &#34;extends&#34;: [ &#34;config:recommended&#34; ], &#34;packageRules&#34;: [ { &#34;matchDatasources&#34;: [&#34;docker&#34;], &#34;pinDigests&#34;: true } ] }This configures Renovate to open pull requests that pin a reference like cgr.dev/chainguard/python:3.12 to a digest like the following:
cgr.dev/chainguard/python:3.12@sha256:e3b524a97c37c32ba590aae0ebcebe3a983c1f69a5093b670fdba980f97a09b3You can also use the matchUpdateTypes option to disable updates for any types other than digest.
Here is an example Renovate configuration that does this:
{ &#34;$schema&#34;: &#34;https://docs.renovatebot.com/renovate-schema.json&#34;, &#34;extends&#34;: [ &#34;config:recommended&#34; ], &#34;packageRules&#34;: [ { &#34;matchDatasources&#34;: [&#34;docker&#34;], &#34;matchUpdateTypes&#34;: [ &#34;major&#34;, &#34;minor&#34;, &#34;patch&#34; ], &#34;enabled&#34;: false } ] }This configures Renovate to update the digest for a reference but not the tag.
The benefit of this approach is that it lets you define your update strategy for each image reference through a mutable tag, rather than having separate rules for different images in your Renovate configuration, similar to Chainguard&rsquo;s Digestabot GitHub Action.
Update packages in Dockerfiles Note: Pin APK packages and images together. Newer images introduced by mutable tags may include newer packages that conflict with your older pinned package versions. If you are pinning package versions then you should also pin the base image to a digest and use Renovate to keep both up to date. This ensures a higher degree of reproducibility and avoids unexpected build failures.
Note: Renovate only supports exact package names. It doesn&rsquo;t resolve provides aliases, so pin the fully-qualified name (e.g argo-cd-2.14, not argo-cd).
Pinned package versions accumulate CVEs over time and may become unavailable as Chainguard removes older versions from its repositories. Renovate&rsquo;s APK datasource (introduced in version 44.97.1) can update apk add pkg=version pins in Dockerfiles, keeping them current as new package versions are released.
For example, the following Dockerfile pins two APK packages that Renovate can bump:
FROM cgr.dev/&lt;org-name&gt;/chainguard-base@sha256:aaaa... RUN apk add --no-cache \ curl=8.12.1-r0 \ jq=1.8.1-r3 Default repositories Chainguard Containers ship with their /etc/apk/repositories file already populated with two public, org-scoped mirrors served from virtualapk.cgr.dev. Neither requires authentication:
virtualapk.cgr.dev/&lt;org-id&gt;/chainguard — open-source packages used in Chainguard&rsquo;s Free container images. virtualapk.cgr.dev/&lt;org-id&gt;/extra-packages — additional packages that aren&rsquo;t fully open source but can still be redistributed by Chainguard. If you aren&rsquo;t modifying /etc/apk/repositories in your build then you should add a packageRules entry to your renovate.json that matches the apk datasource and lists both of the default URLs.
{ &#34;$schema&#34;: &#34;https://docs.renovatebot.com/renovate-schema.json&#34;, &#34;extends&#34;: [ &#34;config:recommended&#34; ], &#34;packageRules&#34;: [ { &#34;matchDatasources&#34;: [&#34;apk&#34;], &#34;registryUrls&#34;: [ &#34;https://virtualapk.cgr.dev/&lt;org-id&gt;/chainguard?arch=x86_64&#34;, &#34;https://virtualapk.cgr.dev/&lt;org-id&gt;/extra-packages?arch=x86_64&#34; ] } ] }Replace &lt;org-id&gt; with your organization&rsquo;s ID, which you can find by running chainctl iam org list -o table.
Set arch=aarch64 if you are building exclusively for that architecture.
In practice, Chainguard publish almost every package with the same versions for each architecture. However, there are some exceptions, so if you are building on both, you may consider having duplicate URLs for each architecture, or having specific packageRules for different Dockerfiles depending on target architecture.
Private repository Your organization-scoped private repository (apk.cgr.dev/&lt;org-name&gt;) serves the packages your organization is entitled to and provides packages that are not available from the public mirrors. To get access to the largest range of packages and versions, you should use it in addition to the default, public repositories.
If you are modifying the /etc/apk/repositories file in your builds to include it, then you should also include it in your Renovate configuration. Since the private repository requires authentication, add a hostRules entry alongside packageRules. The username and password are sourced from Renovate secrets so the credentials themselves stay out of source control:
{ &#34;$schema&#34;: &#34;https://docs.renovatebot.com/renovate-schema.json&#34;, &#34;extends&#34;: [ &#34;config:recommended&#34; ], &#34;hostRules&#34;: [ { &#34;matchHost&#34;: &#34;apk.cgr.dev&#34;, &#34;username&#34;: &#34;{{ secrets.PULL_TOKEN_USERNAME }}&#34;, &#34;password&#34;: &#34;{{ secrets.PULL_TOKEN_PASSWORD }}&#34; } ], &#34;packageRules&#34;: [ { &#34;matchDatasources&#34;: [&#34;apk&#34;], &#34;registryUrls&#34;: [ &#34;https://virtualapk.cgr.dev/&lt;org-id&gt;/chainguard?arch=x86_64&#34;, &#34;https://virtualapk.cgr.dev/&lt;org-id&gt;/extra-packages?arch=x86_64&#34;, &#34;https://apk.cgr.dev/&lt;org-name&gt;?arch=x86_64&#34; ] } ] }Replace &lt;org-name&gt; with your organization&rsquo;s name and &lt;org-id&gt; with your organization&rsquo;s ID, which you can find by running chainctl iam org list -o table.
If your build is exclusively using the private repository then you should remove the public virtualapk.cgr.dev URLs from the list.
For the username and password, you can generate a pull token for long-lived static credentials:
chainctl auth pull-token create --repository=apk --ttl=259200mOr for short-lived credentials, either locally or when using assumable identities, generate an access token that is valid for an hour and use it with the username _token:
chainctl auth token --audience=apk.cgr.devEither way, inject the credentials into the PULL_TOKEN_USERNAME and PULL_TOKEN_PASSWORD secrets at runtime via the RENOVATE_SECRETS environment variable:
export RENOVATE_SECRETS=&#34;{\&#34;PULL_TOKEN_USERNAME\&#34;: \&#34;&lt;username&gt;\&#34;, \&#34;PULL_TOKEN_PASSWORD\&#34;: \&#34;&lt;password&gt;\&#34;}&#34;Alternatively, you can supply the credentials to Renovate in one of two other ways:
Environment variables — set RENOVATE_DETECT_HOST_RULES_FROM_ENV=true and expose the credentials as RENOVATE_APK_APK_CGR_DEV_USERNAME and RENOVATE_APK_APK_CGR_DEV_PASSWORD. Renovate assembles a hostRules entry from these at runtime, so you can drop the hostRules block from renovate.json. The Run Renovate in GitHub Actions and Run Renovate with Docker sections below use this pattern. hostRules in a self-hosted config.js — put the hostRules block in the self-hosted config file, reading credentials from process.env. The Set up credentials for Renovate section above uses this pattern for cgr.dev. Update Chainguard Helm charts in Helmfiles Renovate supports updating Helmfile releases with its built-in helmfile manager. However, it doesn&rsquo;t presently support updating digest references for OCI chart URLs, which is a recommended practice when deploying Chainguard Helm charts. See renovatebot/renovate#45054 for more details.
To pin Chainguard Helm charts to digests and update them with Renovate, you can use a custom jsonata manager as a workaround.
Given a helmfile.yaml such as:
releases: - name: kube-prometheus-stack chart: oci://cgr.dev/&lt;org&gt;/charts/kube-prometheus-stack@sha256:833bd55297054df0afdbe47750013b8e2eff930059c63c0746447fa8d0b729d3 version: 87.4.0 namespace: monitoring - name: nginx chart: oci://cgr.dev/&lt;org&gt;/iamguarded-charts/nginx@sha256:7b88d44da254fc764171da809471d10c6cf15b9ab0ddcb4b475b9a8f380aeb79 version: 22.1.0 namespace: nginxConfigure Renovate with the following example, replacing every instance of cgr.dev/&lt;org&gt; with your Chainguard organization or internal mirror or proxy.
{ &#34;$schema&#34;: &#34;https://docs.renovatebot.com/renovate-schema.json&#34;, &#34;packageRules&#34;: [ { &#34;matchManagers&#34;: [&#34;helmfile&#34;], &#34;matchPackagePatterns&#34;: [ &#34;^cgr\\.dev/&lt;org&gt;/(charts|iamguarded-charts)/&#34; ], &#34;enabled&#34;: false } ], &#34;customManagers&#34;: [ { &#34;customType&#34;: &#34;jsonata&#34;, &#34;fileFormat&#34;: &#34;yaml&#34;, &#34;fileMatch&#34;: [&#34;(^|/)helmfile\\.ya?ml$&#34;], &#34;matchStrings&#34;: [ &#34;releases[$contains(chart, &#39;cgr.dev/&lt;org&gt;/charts/&#39;)].($n := $substringAfter($substringBefore(chart &amp; &#39;@&#39;, &#39;@&#39;), &#39;charts/&#39;); $exists(version) ? { &#39;depName&#39;: $n, &#39;packageName&#39;: &#39;cgr.dev/&lt;org&gt;/charts/&#39; &amp; $n, &#39;currentValue&#39;: version, &#39;currentDigest&#39;: $substringAfter(chart, &#39;@&#39;) } : { &#39;depName&#39;: $n, &#39;packageName&#39;: &#39;cgr.dev/&lt;org&gt;/charts/&#39; &amp; $n, &#39;currentDigest&#39;: $substringAfter(chart, &#39;@&#39;) })&#34; ], &#34;datasourceTemplate&#34;: &#34;docker&#34; }, { &#34;customType&#34;: &#34;jsonata&#34;, &#34;fileFormat&#34;: &#34;yaml&#34;, &#34;fileMatch&#34;: [&#34;(^|/)helmfile\\.ya?ml$&#34;], &#34;matchStrings&#34;: [ &#34;releases[$contains(chart, &#39;cgr.dev/&lt;org&gt;/iamguarded-charts/&#39;)].($n := $substringAfter($substringBefore(chart &amp; &#39;@&#39;, &#39;@&#39;), &#39;iamguarded-charts/&#39;); $exists(version) ? { &#39;depName&#39;: $n, &#39;packageName&#39;: &#39;cgr.dev/&lt;org&gt;/iamguarded-charts/&#39; &amp; $n, &#39;currentValue&#39;: version, &#39;currentDigest&#39;: $substringAfter(chart, &#39;@&#39;) } : { &#39;depName&#39;: $n, &#39;packageName&#39;: &#39;cgr.dev/&lt;org&gt;/iamguarded-charts/&#39; &amp; $n, &#39;currentDigest&#39;: $substringAfter(chart, &#39;@&#39;) })&#34; ], &#34;datasourceTemplate&#34;: &#34;docker&#34; } ] } Update Chainguard Helm charts in ArgoCD applications Renovate supports updating ArgoCD Application manifests with its built-in argocd manager. However, it doesn&rsquo;t presently support updating digest references for OCI chart URLs, which is a recommended practice when deploying Chainguard Helm charts. See renovatebot/renovate#45055 for more details.
To pin Chainguard Helm charts to digests and update them with Renovate, you can use a custom jsonata manager as a workaround.
Given Application manifests such as:
apiVersion: argoproj.io/v1alpha1 kind: Application metadata: name: kube-prometheus-stack spec: source: repoURL: oci://cgr.dev/&lt;org&gt;/charts chart: kube-prometheus-stack targetRevision: 87.4.0@sha256:833bd55297054df0afdbe47750013b8e2eff930059c63c0746447fa8d0b729d3 --- apiVersion: argoproj.io/v1alpha1 kind: Application metadata: name: nginx spec: source: repoURL: oci://cgr.dev/&lt;org&gt;/iamguarded-charts chart: nginx targetRevision: 22.1.0@sha256:7b88d44da254fc764171da809471d10c6cf15b9ab0ddcb4b475b9a8f380aeb79Configure Renovate as in the following example, replacing every instance of cgr.dev/&lt;org&gt; with your Chainguard organization or internal mirror or proxy.
{ &#34;$schema&#34;: &#34;https://docs.renovatebot.com/renovate-schema.json&#34;, &#34;packageRules&#34;: [ { &#34;matchManagers&#34;: [&#34;argocd&#34;], &#34;matchPackagePatterns&#34;: [ &#34;^cgr\\.dev/&lt;org&gt;/(charts|iamguarded-charts)/&#34; ], &#34;enabled&#34;: false } ], &#34;customManagers&#34;: [ { &#34;customType&#34;: &#34;jsonata&#34;, &#34;fileFormat&#34;: &#34;yaml&#34;, &#34;fileMatch&#34;: [&#34;\\.ya?ml$&#34;], &#34;matchStrings&#34;: [ &#34;spec.source[$contains(repoURL, &#39;cgr.dev/&lt;org&gt;/charts&#39;)].($tr := targetRevision; $substring($tr, 0, 7) = &#39;sha256:&#39; ? { &#39;depName&#39;: chart, &#39;packageName&#39;: &#39;cgr.dev/&lt;org&gt;/charts/&#39; &amp; chart, &#39;currentDigest&#39;: $tr } : { &#39;depName&#39;: chart, &#39;packageName&#39;: &#39;cgr.dev/&lt;org&gt;/charts/&#39; &amp; chart, &#39;currentValue&#39;: $substringBefore($tr &amp; &#39;@&#39;, &#39;@&#39;), &#39;currentDigest&#39;: $substringAfter($tr, &#39;@&#39;) })&#34; ], &#34;datasourceTemplate&#34;: &#34;docker&#34; }, { &#34;customType&#34;: &#34;jsonata&#34;, &#34;fileFormat&#34;: &#34;yaml&#34;, &#34;fileMatch&#34;: [&#34;\\.ya?ml$&#34;], &#34;matchStrings&#34;: [ &#34;spec.source[$contains(repoURL, &#39;cgr.dev/&lt;org&gt;/iamguarded-charts&#39;)].($tr := targetRevision; $substring($tr, 0, 7) = &#39;sha256:&#39; ? { &#39;depName&#39;: chart, &#39;packageName&#39;: &#39;cgr.dev/&lt;org&gt;/iamguarded-charts/&#39; &amp; chart, &#39;currentDigest&#39;: $tr } : { &#39;depName&#39;: chart, &#39;packageName&#39;: &#39;cgr.dev/&lt;org&gt;/iamguarded-charts/&#39; &amp; chart, &#39;currentValue&#39;: $substringBefore($tr &amp; &#39;@&#39;, &#39;@&#39;), &#39;currentDigest&#39;: $substringAfter($tr, &#39;@&#39;) })&#34; ], &#34;datasourceTemplate&#34;: &#34;docker&#34; } ] } Update Chainguard Helm charts in Flux Renovate natively supports updating Flux OCIRepository resources with its built-in flux manager.
Given a Flux manifest such as:
--- apiVersion: source.toolkit.fluxcd.io/v1 kind: OCIRepository metadata: name: kube-prometheus-stack namespace: monitoring spec: interval: 5m url: oci://cgr.dev/&lt;org&gt;/charts/kube-prometheus-stack ref: tag: 87.4.0 digest: sha256:833bd55297054df0afdbe47750013b8e2eff930059c63c0746447fa8d0b729d3 --- apiVersion: helm.toolkit.fluxcd.io/v2 kind: HelmRelease metadata: name: kube-prometheus-stack namespace: monitoring spec: interval: 5m chartRef: kind: OCIRepository name: kube-prometheus-stackConfigure Renovate with the following example, adjusting the flux.fileMatch patterns to cover your repository layout. The pinDigests rule enforces the recommended practice of pinning charts to a digest: if an OCIRepository has a tag but no digest, Renovate opens a pull request to add one.
{ &#34;$schema&#34;: &#34;https://docs.renovatebot.com/renovate-schema.json&#34;, &#34;flux&#34;: { &#34;fileMatch&#34;: [ &#34;(^|/)flux\\.ya?ml$&#34;, &#34;(^|/)gotk-components\\.ya?ml$&#34; ] }, &#34;packageRules&#34;: [ { &#34;matchManagers&#34;: [&#34;flux&#34;], &#34;matchDatasources&#34;: [&#34;docker&#34;], &#34;matchPackagePatterns&#34;: [ &#34;^cgr\\.dev/&lt;org&gt;/(charts|iamguarded-charts)/&#34; ], &#34;pinDigests&#34;: true } ] } Run Renovate in GitHub Actions You can use renovatebot/github-action to run Renovate from a GitHub Actions workflow. This can be combined with an assumable identity to authenticate to cgr.dev and update references to Chainguard container images in your repository.
Note: This section assumes you have permissions to create identities in your Chainguard organization.
First, create a Renovate configuration file at the root of your GitHub repository. Refer to the official documentation for all the supported options.
This is an example of a minimal configuration:
{ &#34;$schema&#34;: &#34;https://docs.renovatebot.com/renovate-schema.json&#34; }Push this file to the main branch of your repository.
Next, create an assumable identity for your GitHub repository. The --github-repo value embeds GitHub&rsquo;s immutable numeric owner and repository IDs; refer to Finding your repository&rsquo;s numeric identifiers for how to retrieve them and when the format applies.
chainctl iam identities create github &lt;identity-name&gt; \ --github-repo=&lt;github-org&gt;@&lt;owner-id&gt;/&lt;github-repo-name&gt;@&lt;repo-id&gt; \ --github-ref=refs/heads/main \ --role=registry.pull,apk.pullCreate a workflow file named .github/workflows/renovate.yaml with the following content. Replace &lt;identity-id&gt; with the ID returned by the previous command.
name: Renovate on: workflow_dispatch: schedule: - cron: &#34;0 3 * * *&#34; permissions: contents: read jobs: renovate: name: Renovate runs-on: ubuntu-latest permissions: contents: write pull-requests: write issues: write id-token: write steps: - uses: chainguard-dev/setup-chainctl@be0acd273acf04bfdf91f51198327e719f6af978 # v0.4.0 with: identity: &#34;&lt;identity-id&gt;&#34; - shell: bash run: | RENOVATE_DOCKER_CGR_DEV_PASSWORD=$(chainctl auth token --audience=cgr.dev) echo &#34;::add-mask::$RENOVATE_DOCKER_CGR_DEV_PASSWORD&#34; echo &#34;RENOVATE_DOCKER_CGR_DEV_PASSWORD=$RENOVATE_DOCKER_CGR_DEV_PASSWORD&#34; &gt;&gt; $GITHUB_ENV RENOVATE_APK_APK_CGR_DEV_PASSWORD=$(chainctl auth token --audience=apk.cgr.dev) echo &#34;::add-mask::$RENOVATE_APK_APK_CGR_DEV_PASSWORD&#34; echo &#34;RENOVATE_APK_APK_CGR_DEV_PASSWORD=$RENOVATE_APK_APK_CGR_DEV_PASSWORD&#34; &gt;&gt; $GITHUB_ENV - name: Run Renovate uses: renovatebot/github-action@6927a58a017ee9ac468a34a5b0d2a9a9bd45cac3 # v43.0.11 env: RENOVATE_TOKEN: ${{ secrets.GITHUB_TOKEN }} RENOVATE_REPOSITORIES: ${{ github.repository }} RENOVATE_DETECT_HOST_RULES_FROM_ENV: &#34;true&#34; RENOVATE_DOCKER_CGR_DEV_USERNAME: &#34;_token&#34; RENOVATE_APK_APK_CGR_DEV_USERNAME: &#34;_token&#34;This workflow performs the following steps:
Installs chainctl and logs in as the assumable identity you created. Exports short-lived tokens for cgr.dev and apk.cgr.dev as RENOVATE_DOCKER_CGR_DEV_PASSWORD and RENOVATE_APK_APK_CGR_DEV_PASSWORD. Runs Renovate with RENOVATE_DETECT_HOST_RULES_FROM_ENV=true so that it uses the passwords exported by the previous step. Push this file to your repository&rsquo;s main branch.
This workflow is scheduled to run at 3:00 a.m. every morning. You can trigger it manually by navigating to Actions &gt; Renovate and selecting Run workflow.
Once the workflow has run successfully, you&rsquo;ll find pull requests in your repository for any image references that need to be updated.
Run Renovate with Docker Chainguard provides an image for Renovate. This is an example of how you can run this image to keep references to Chainguard images up to date in a GitHub repository.
Note: To follow along with this section, you must have access to Chainguard&rsquo;s renovate container image.
To begin, generate a Personal Access Token for your GitHub user as described in Renovate&rsquo;s official documentation.
Export the token as an environment variable named RENOVATE_TOKEN:
export RENOVATE_TOKEN=ghp_XXXXXXXXXXXXXXXXXXNext, create a Renovate configuration file at the root of any GitHub repositories you want to target with Renovate. Refer to the official documentation for all the supported options.
This is an example of a minimal configuration:
{ &#34;$schema&#34;: &#34;https://docs.renovatebot.com/renovate-schema.json&#34; }Then, log in with chainctl:
chainctl auth loginFinally, run Renovate. Substitute &lt;org-name&gt; with the name of your Chainguard organization and provide any GitHub repositories that you want to target as arguments in the form &lt;github-org&gt;/&lt;github-repo-name&gt;:
docker run \ -it \ --rm \ -e RENOVATE_TOKEN=&#34;${RENOVATE_TOKEN}&#34; \ -e RENOVATE_DETECT_HOST_RULES_FROM_ENV=true \ -e RENOVATE_DOCKER_CGR_DEV_USERNAME=_token \ -e RENOVATE_DOCKER_CGR_DEV_PASSWORD=$(chainctl auth token --audience cgr.dev) \ -e RENOVATE_APK_APK_CGR_DEV_USERNAME=_token \ -e RENOVATE_APK_APK_CGR_DEV_PASSWORD=$(chainctl auth token --audience apk.cgr.dev) \ cgr.dev/&lt;org-name&gt;/renovate \ &lt;github-org&gt;/&lt;github-repo-name&gt;This example passes short-lived tokens for cgr.dev and apk.cgr.dev using the RENOVATE_DOCKER_CGR_DEV_PASSWORD and RENOVATE_APK_APK_CGR_DEV_PASSWORD environment variables.
Troubleshooting Renovate doesn&rsquo;t behave as expected Run Renovate in debug mode and dump the resolved configuration to understand how it interpreted your settings.
For example:
LOG_LEVEL=debug renovate --print-config ... &#34;hostRules&#34;: [ { &#34;hostType&#34;: &#34;docker&#34;, &#34;matchHost&#34;: &#34;cgr.dev&#34;, &#34;username&#34;: &#34;&lt;identity-id&gt;&#34;, &#34;password&#34;: &#34;***********&#34;, &#34;resolvedHost&#34;: &#34;cgr.dev&#34; }, {&#34;matchHost&#34;: null, &#34;hostType&#34;: &#34;local&#34;} ] ... DEBUG: hostRules: basic auth for https://cgr.dev (repository=local) DEBUG: getLabels(https://cgr.dev, ORGANIZATION/static, latest) (repository=local) DEBUG: getManifestResponse(https://cgr.dev, ORGANIZATION/static, latest, get) (repository=local) DEBUG: getManifestResponse(https://cgr.dev, ORGANIZATION/static, sha256:76d71eb53b1b44ec955529ece91c6da222a54fed660ca6b25124935bdd96e133, get) (repository=local) DEBUG: found labels in manifest (repository=local) &#34;labels&#34;: { &#34;dev.chainguard.package.main&#34;: &#34;static&#34;, &#34;org.opencontainers.image.authors&#34;: &#34;Chainguard Team https://www.chainguard.dev/&#34;, &#34;org.opencontainers.image.created&#34;: &#34;2024-12-04T19:55:37Z&#34;, &#34;org.opencontainers.image.source&#34;: &#34;https://github.com/chainguard-images/images-private/tree/main/images/static&#34;, &#34;org.opencontainers.image.url&#34;: &#34;https://images.chainguard.dev/directory/image/static/overview?utm_source=cg-academy&amp;utm_medium=referral&amp;utm_campaign=dev-enablement&amp;utm_content=edu-content-chainguard-chainguard-images-working-with-images-renovate&#34;, &#34;org.opencontainers.image.vendor&#34;: &#34;Chainguard&#34; } Connections to cgr.dev fail If you have problems getting Renovate to monitor cgr.dev, double-check the connection details. Make sure the token is still valid (you can verify with chainctl iam identities list) and it has access to the repository you are referring to. You can test these credentials by running a docker login and docker pull in a clean environment.
The log shows a getReleaseList error You may encounter errors such as the following:
DEBUG: getReleaseList error (repository=chainguard-images/images-private, branch=renovate/cgr.dev-chainguard.edu-python-3.x) &#34;type&#34;: &#34;github&#34;, &#34;apiBaseUrl&#34;: &#34;https://api.github.com/&#34;, &#34;err&#34;: { &#34;message&#34;: &#34;`chainguard-images` forbids access via a personal access token (classic). Please use a GitHub App, OAuth App, or a personal access token with fine-grained permissions.&#34;, &#34;stack&#34;: &#34;Error: `chainguard-images` forbids access via a personal access token (classic). Please use a GitHub App, OAuth App, or a personal access token with fine-grained permissions.\n at …These can be safely ignored. They are caused by Renovate using the org.opencontainers.image.source label on our images to look for a changelog. As this source is set to the private images-private GitHub repository, this request fails.
Learn more Using Digestabot with Chainguard Containers covers Chainguard&rsquo;s own GitHub Action for keeping digest-pinned references current. Using Dependabot with Chainguard Containers covers the equivalent setup for teams already using Dependabot. Strategies and tooling for updating containers compares the wider range of update tools. Considerations for keeping containers up to date covers the tradeoffs behind an update policy. Authenticating to the Chainguard registry documents pull tokens and the other authentication options in full. Renovate&rsquo;s APK datasource documentation covers every registryUrl query parameter Renovate supports. 
