Already running Renovate? Bivouac layers on top, doesn't replace it.
Renovate opens the PR, sets the title, and bumps the lockfile. That is the easy half. The other half — the review queue, the merge button, the on-call rotation that decides between forward fix and downgrade — still sits on a human's plate. For any team with weekly PR volume, "open PR" is no longer the same moment as "ready for review." Bivouac layers Investigate → Fix → Test → Review on top of the same PR stream Renovate already opens, so the queue arrives with green-test evidence instead of accumulating on the reviewer.
- 01Investigate
- 02Fix
- 03Test
- 04Review
The four-stop flow
What Bivouac adds on top of the PR Renovate already opens.
Renovate does the easy half — the PR, the lockfile bump, the branch. Bivouac picks up the queue-management half, the four stops a Renovate-only patch PR still needs to clear before it shows up on main.
- 01Investigate
Renovate opens the PR; Bivouac reads the lockfile diff, the SemVer-major upstream change, and the advisory source behind each bump so the decision between forward fix, downgrade, and pin is solved locally — not left to whoever opens the PR first.
- 02Fix
Renovate ships a locked lockfile patch; Bivouac selects forward fix, downgrade, or pin from the repo’s policy pack, so the version chosen for each surface (monorepo, microservice, lockfile-strict) is the one your policy picked — not the one Renovate set first.
- 04Test
The PR is reviewable only after the repo’s own test suite runs on CI. Bivouac’s policy pack gates the “ready for review” state on a green build — a human retains the merge button after the evidence is ready.
- 05Review
On green tests, Bivouac leaves a reviewable PR and waits for approval. The on-call is paged only on the contested outcomes — license changes, public-API breaks, security-sensitive surfaces — and every row carries feed source, decision rationale, test output, and review outcome.
Same Renovate config, kept.The dependency-manager config you already wrote — group rules, schedule, lockfile mode — does not move. Bivouac reads the PR stream Renovate produces; nothing on Renovate's side has to change.
The headline difference
Same Renovate, smaller queue.
The deep comparison lives on /vs/renovate. The short version is below — one sentence, every word drawn from the same source as the comparison page.
Bivouac vs Renovate
Caveat — Useful — but the human still owns the decision tree.Verbatim from the “How Bivouc compares” research on the landing page.
Read next
Three field reports for teams already running Renovate.
Benchmark numbers, picking framework, and the Snyk comparison — three posts that teed up the layering story this page tells.
- /blog/cve-2025-benchmarks
Field report · CVE handling
Five months of side-by-side CVE handling data — patch latency, test pass-rate, reviewer load. Short version: less time on-call, fewer rollbacks.
- /blog/dependency-comparison-guide
Guide · picking a dependency manager
A four-step framework: pin the change, time the on-call load, measure the lockfile diff, look at the rollback rate. Every Renovate → Dependabot migration we run uses it.
- /blog/bivouac-vs-snyk-open-source
Comparison · advisory feeds
Same NVD + GHSA feeds, very different ending: tested patch PRs vs dashboard rows. Where the two diverge, and which catches the CVE before the on-call wakes up.
Layer it on, don’t replace it
One repo, same Renovate, smaller queue by end of week.
Renovate runs as it does today — your config, your schedule, your lockfile rules. Bivouac sits on top, owns the review policy per surface, and pages only on the contested outcomes. Free for the first repo, no card to start.
Free for the first repo. No card to start.