ci: host the shared renovate preset and adopt it #57
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-docs!57
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "ci/renovate-config-tweak"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Seven repos carried near-identical
renovate.jsonfiles, hand-synced and already drifted —lockFileMaintenancewas in four of them and missing from the other three. This hosts the sharedconfiguration here and reduces every repo to an
extends.Why
default.jsonRenovate resolves an unnamed preset (
local>gitborg/gitborg-docs) todefault.jsonin the reporoot — hence the filename rather than something more descriptive.
local>resolves against thecurrent platform, so preset lookup stays on
git.gitborg.sewith no external service consulted(principle 1). The preset is public, which is what lets the private repos extend it; it contains
policy, never secrets.
Two corrections to the config being consolidated
1.
major: {enabled: false}→major: {dependencyDashboardApproval: true}.Disabling majors stops them being created, so they never reach the Dependency Dashboard either — we
would simply stop being told that a new Forgejo or Postgres major exists. In
bitborg-infrait alsomade this pre-existing rule dead config:
Its intent is gated but visible;
enabled: falsesilently turned that into invisible. Gatingglobally keeps the signal while still preventing unsolicited PRs.
It also keeps majors available to security remediation. Whether a vulnerability fix requiring a major
bump survives
enabled: falseis not clear from the Renovate docs, and the summary I could retrievecontradicted itself on
vulnerabilityAlertsdefaults — so rather than depend on an override thatcould not be verified, majors stay enabled and gated, which removes the question.
2. Labels now use the shared vocabulary.
labels: ["dependencies"]and["security", "dependencies"]reference labels that are not incontributing/issue-tracking.mdand do not exist on the repos, so Renovate would have dropped themsilently. Replaced with
type/chore, andtype/chore+area/securityfor vulnerability PRs.One addition
minimumReleaseAge: "3 days"quarantines fresh releases against the compromised-publish pattern(principle 4).
vulnerabilityAlertsoverrides it to zero so security fixes are never delayed — pinnedexplicitly rather than inherited, so changing the global value cannot slow a security fix. It has to
be a duration string;
0fails validation, which is how the first attempt was caught.Verification
All eight config files pass
renovate-config-validatoragainst Renovate 43, the version theservices host deploys (
renovate:43in the role's defaults).Version matters here:
npxinitially resolved validator 37.440.7, which rejectedcustomManagers[*].managerFilePatternsas a disallowed field — a false positive against configalready live on
main, since that option postdates v37. Worth remembering before acting on avalidator complaint about existing config.
Effects to expect
rangeStrategy: "pin"is a no-op in most repos — dependencies are already exact. It will produceone small pinning PR in this repo (
markdownlint-cli2: ^0.23.1) and inbitborg-internal(
lefthook: ^2.1.9).:dependencyDashboardis redundant (config:recommendedincludes it) and kept as explicit intent.Merge order matters
Merge this PR first. Six repos now point at a preset that does not exist until this lands, and if
local>gitborg/gitborg-docsfails to resolve, all of them lose their Renovate config at once. Suggestedsequence: this PR → one adopter (
bitborg-internalis the lowest-risk, being private) → confirm thenext Renovate run resolves the preset → then the remaining five.
The
local>mechanism cannot be verified locally:renovate-config-validatorhas no platform access,so preset resolution is only exercised on a real run.
Seven repos carried near-identical renovate.json files, hand-synced and already drifted. The common configuration now lives here in default.json — Renovate resolves an unnamed preset (`local>gitborg/gitborg-docs`) to default.json, which is why the file is not called renovate-config.json. A policy change is one PR instead of seven. Two corrections to the config being consolidated: `major: {enabled: false}` becomes `major: {dependencyDashboardApproval: true}`. Disabling majors stops them being created at all, so they never reach the Dependency Dashboard either — we would simply stop being told a new Forgejo or Postgres major exists. In gitborg-infra it also made the existing forgejo/postgres dashboard-approval rule dead config, silently changing "gated and visible" into "invisible". Gating keeps the signal while still preventing unsolicited PRs, and keeps majors available to security remediation, which enabled:false may block (the docs are ambiguous on that interaction, so this avoids depending on it). Labels now use the shared vocabulary from contributing/issue-tracking.md — type/chore, and type/chore + area/security for vulnerability PRs. The previous `dependencies` and `security` labels are not in that vocabulary and do not exist on the repos, so Renovate would have dropped them silently. Also adds minimumReleaseAge of 3 days as a quarantine against the compromised-publish pattern (principle 4), with vulnerabilityAlerts overriding it to zero so security fixes are never delayed. That override is pinned explicitly rather than inherited, so changing the global value cannot slow a security fix. It must be a duration string — `0` fails validation. ADR 0023 records the preset, its policy choices, and that onboarding now starts new repos on it. Validated with renovate-config-validator against Renovate 43, the version the services host runs.