ci: host the shared renovate preset and adopt it #57

Sammanfogat
supernaut sammanfogade 2 incheckningar från ci/renovate-config-tweak in i main 2026-07-30 15:14:18 +00:00
Ägare

Seven repos carried near-identical renovate.json files, hand-synced and already drifted —
lockFileMaintenance was in four of them and missing from the other three. This hosts the shared
configuration here and reduces every repo to an extends.

Why default.json

Renovate resolves an unnamed preset (local>gitborg/gitborg-docs) to default.json in the repo
root — hence the filename rather than something more descriptive. local> resolves against the
current platform, so preset lookup stays on git.gitborg.se with no external service consulted
(principle 1). The preset is public, which is what lets the private repos extend it; it contains
policy, never secrets.

Two corrections to the config being consolidated

1. major: {enabled: false} → major: {dependencyDashboardApproval: true}.

Disabling majors stops them being created, so they never reach the Dependency Dashboard either — we
would simply stop being told that a new Forgejo or Postgres major exists. In bitborg-infra it also
made this pre-existing rule dead config:

{
  "description": "Major bumps of the git server and the database follow the runbook...
                  hold them behind Dependency Dashboard approval instead of auto-opening PRs.",
  "matchDepNames": ["codeberg.org/forgejo/forgejo", "docker.io/library/postgres"],
  "matchUpdateTypes": ["major"],
  "dependencyDashboardApproval": true
}

Its intent is gated but visible; enabled: false silently turned that into invisible. Gating
globally keeps the signal while still preventing unsolicited PRs.

It also keeps majors available to security remediation. Whether a vulnerability fix requiring a major
bump survives enabled: false is not clear from the Renovate docs, and the summary I could retrieve
contradicted itself on vulnerabilityAlerts defaults — so rather than depend on an override that
could not be verified, majors stay enabled and gated, which removes the question.

2. Labels now use the shared vocabulary.

labels: ["dependencies"] and ["security", "dependencies"] reference labels that are not in
contributing/issue-tracking.md and do not exist on the repos, so Renovate would have dropped them
silently. Replaced with type/chore, and type/chore + area/security for vulnerability PRs.

One addition

minimumReleaseAge: "3 days" quarantines fresh releases against the compromised-publish pattern
(principle 4). vulnerabilityAlerts overrides it to zero so security fixes are never delayed — pinned
explicitly rather than inherited, so changing the global value cannot slow a security fix. It has to
be a duration string; 0 fails validation, which is how the first attempt was caught.

Verification

All eight config files pass renovate-config-validator against Renovate 43, the version the
services host deploys (renovate:43 in the role's defaults).

Version matters here: npx initially resolved validator 37.440.7, which rejected
customManagers[*].managerFilePatterns as a disallowed field — a false positive against config
already live on main, since that option postdates v37. Worth remembering before acting on a
validator complaint about existing config.

Effects to expect

  • rangeStrategy: "pin" is a no-op in most repos — dependencies are already exact. It will produce
    one small pinning PR in this repo (markdownlint-cli2: ^0.23.1) and in bitborg-internal
    (lefthook: ^2.1.9).
  • :dependencyDashboard is redundant (config:recommended includes it) and kept as explicit intent.

Merge order matters

Merge this PR first. Six repos now point at a preset that does not exist until this lands, and if
local>gitborg/gitborg-docs fails to resolve, all of them lose their Renovate config at once. Suggested
sequence: this PR → one adopter (bitborg-internal is the lowest-risk, being private) → confirm the
next Renovate run resolves the preset → then the remaining five.

The local> mechanism cannot be verified locally: renovate-config-validator has no platform access,
so preset resolution is only exercised on a real run.

Seven repos carried near-identical `renovate.json` files, hand-synced and already drifted — `lockFileMaintenance` was in four of them and missing from the other three. This hosts the shared configuration here and reduces every repo to an `extends`. ## Why `default.json` Renovate resolves an **unnamed** preset (`local>gitborg/gitborg-docs`) to `default.json` in the repo root — hence the filename rather than something more descriptive. `local>` resolves against the current platform, so preset lookup stays on `git.gitborg.se` with no external service consulted (principle 1). The preset is public, which is what lets the private repos extend it; it contains policy, never secrets. ## Two corrections to the config being consolidated **1. `major: {enabled: false}` → `major: {dependencyDashboardApproval: true}`.** Disabling majors stops them being *created*, so they never reach the Dependency Dashboard either — we would simply stop being told that a new Forgejo or Postgres major exists. In `bitborg-infra` it also made this pre-existing rule dead config: ```json { "description": "Major bumps of the git server and the database follow the runbook... hold them behind Dependency Dashboard approval instead of auto-opening PRs.", "matchDepNames": ["codeberg.org/forgejo/forgejo", "docker.io/library/postgres"], "matchUpdateTypes": ["major"], "dependencyDashboardApproval": true } ``` Its intent is *gated but visible*; `enabled: false` silently turned that into *invisible*. Gating globally keeps the signal while still preventing unsolicited PRs. It also keeps majors available to security remediation. Whether a vulnerability fix requiring a major bump survives `enabled: false` is not clear from the Renovate docs, and the summary I could retrieve contradicted itself on `vulnerabilityAlerts` defaults — so rather than depend on an override that could not be verified, majors stay enabled and gated, which removes the question. **2. Labels now use the shared vocabulary.** `labels: ["dependencies"]` and `["security", "dependencies"]` reference labels that are not in `contributing/issue-tracking.md` and do not exist on the repos, so Renovate would have dropped them silently. Replaced with `type/chore`, and `type/chore` + `area/security` for vulnerability PRs. ## One addition `minimumReleaseAge: "3 days"` quarantines fresh releases against the compromised-publish pattern (principle 4). `vulnerabilityAlerts` overrides it to zero so security fixes are never delayed — pinned explicitly rather than inherited, so changing the global value cannot slow a security fix. It has to be a duration **string**; `0` fails validation, which is how the first attempt was caught. ## Verification All eight config files pass `renovate-config-validator` **against Renovate 43**, the version the services host deploys (`renovate:43` in the role's defaults). Version matters here: `npx` initially resolved validator **37.440.7**, which rejected `customManagers[*].managerFilePatterns` as a disallowed field — a false positive against config already live on `main`, since that option postdates v37. Worth remembering before acting on a validator complaint about existing config. ## Effects to expect - `rangeStrategy: "pin"` is a no-op in most repos — dependencies are already exact. It will produce one small pinning PR in this repo (`markdownlint-cli2: ^0.23.1`) and in `bitborg-internal` (`lefthook: ^2.1.9`). - `:dependencyDashboard` is redundant (`config:recommended` includes it) and kept as explicit intent. ## Merge order matters **Merge this PR first.** Six repos now point at a preset that does not exist until this lands, and if `local>gitborg/gitborg-docs` fails to resolve, all of them lose their Renovate config at once. Suggested sequence: this PR → one adopter (`bitborg-internal` is the lowest-risk, being private) → confirm the next Renovate run resolves the preset → then the remaining five. The `local>` mechanism cannot be verified locally: `renovate-config-validator` has no platform access, so preset resolution is only exercised on a real run.
supernaut lade till 2 incheckningar 2026-07-30 15:12:48 +00:00
ci: host the shared renovate preset and adopt it
Alla kontroller lyckades
ci / ci (pull_request) Successful in 13s
a207fc8f24
Seven repos carried near-identical renovate.json files, hand-synced and already
drifted. The common configuration now lives here in default.json — Renovate
resolves an unnamed preset (`local>gitborg/gitborg-docs`) to default.json, which
is why the file is not called renovate-config.json. A policy change is one PR
instead of seven.

Two corrections to the config being consolidated:

`major: {enabled: false}` becomes `major: {dependencyDashboardApproval: true}`.
Disabling majors stops them being created at all, so they never reach the
Dependency Dashboard either — we would simply stop being told a new Forgejo or
Postgres major exists. In gitborg-infra it also made the existing
forgejo/postgres dashboard-approval rule dead config, silently changing "gated
and visible" into "invisible". Gating keeps the signal while still preventing
unsolicited PRs, and keeps majors available to security remediation, which
enabled:false may block (the docs are ambiguous on that interaction, so this
avoids depending on it).

Labels now use the shared vocabulary from contributing/issue-tracking.md —
type/chore, and type/chore + area/security for vulnerability PRs. The previous
`dependencies` and `security` labels are not in that vocabulary and do not exist
on the repos, so Renovate would have dropped them silently.

Also adds minimumReleaseAge of 3 days as a quarantine against the
compromised-publish pattern (principle 4), with vulnerabilityAlerts overriding it
to zero so security fixes are never delayed. That override is pinned explicitly
rather than inherited, so changing the global value cannot slow a security fix.
It must be a duration string — `0` fails validation.

ADR 0023 records the preset, its policy choices, and that onboarding now starts
new repos on it.

Validated with renovate-config-validator against Renovate 43, the version the
services host runs.
supernaut sammanfogade incheckning 9e7216f22a till main 2026-07-30 15:14:18 +00:00
supernaut tog bort grenen ci/renovate-config-tweak 2026-07-30 15:14:19 +00:00
supernaut refererade denna ändringsförfrågan från en incheckning 2026-07-30 15:14:20 +00:00
supernaut refererade denna ändringsförfrågan från en incheckning 2026-08-03 09:41:31 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-docs!57
Ingen beskrivning angiven.