fix(renovate): give hand-written security overrides the fast path #85

Sammanfogat
supernaut sammanfogade 1 incheckning från fix/override-security-fast-path in i main 2026-08-16 13:36:49 +00:00
Ägare

Closes bitborg/bitborg-infra#331.

The hole

The preset's stated intent is that a security fix is never delayed by a global setting. That
exemption lives under vulnerabilityAlerts. It reaches only updates Renovate itself classifies as
alerts.

A vulnerability remediated by hand as a package-manager override is an ordinary dependency to
Renovate. So it fell under the global minimumReleaseAge: "3 days". Observed 2026-08-02:
brace-expansion@<=5.0.7 sat in Pending Status Checks on the portal, held by the quarantine.

The fix

A packageRules entry matching the override mechanism in every shape it takes. npm and yarn
overrides and resolutions. pnpm's pnpm.overrides in package.json.
pnpm-workspace.overrides in pnpm-workspace.yaml.

Two things worth flagging

The pnpm-workspace depType is pnpm-workspace.overrides, not pnpm.overrides. I checked the npm
manager docs rather than inferring it from the package.json field name. Inferring would have been
wrong. This matters here: a depType that matches nothing fails silently and looks identical to a
rule that works. That is the same class of hole this PR closes. No validator catches it either,
since depTypes are free-form strings.

schedule is needed as well as minimumReleaseAge. The issue proposed only the release age. The
global schedule is before 6am on monday. Zeroing the quarantine alone would still leave the PR
waiting for the weekly window. That misses the issue's own acceptance criterion, "on the run
following its upstream release", by up to six days. Both are set now, matching how
vulnerabilityAlerts already does it.

Trade-off

An override bump now skips the supply-chain quarantine even when the bump is not security work.
That is a real loss. The quarantine exists to avoid pulling a freshly published compromised
version.

It is still the better side of the trade. Overrides are rare, hand-written and reviewed, so the
exposure is narrow. The alternative is leaving a known vulnerability pinned for three extra days.
The reasoning is recorded in the rule's description.

Say the word if you would rather scope this to pnpm-workspace.overrides only. Narrowing it is a
one-line change.

Verification

Validated with renovate-config-validator pinned to the deployed major (43.288.0), per #331 and
the false-positive problem recorded in #256:

INFO: Config validated successfully against 1 file(s)

That result is not vacuous. With a deliberately typo'd key injected, the same command fails:

ERROR: Found errors in configuration
       "message": "Invalid configuration option: packageRules[1].minimumReleaseAgeTYPO"

Acceptance

#331 asks that a security override bump appears as a PR on the run following its upstream release.
The next serialize-javascript@<=7.0.2 bump to 7.1.0, already pending on the portal's dashboard,
is the natural first observation.

Closes bitborg/bitborg-infra#331. ## The hole The preset's stated intent is that a security fix is never delayed by a global setting. That exemption lives under `vulnerabilityAlerts`. It reaches only updates Renovate itself classifies as alerts. A vulnerability remediated by hand as a package-manager override is an ordinary dependency to Renovate. So it fell under the global `minimumReleaseAge: "3 days"`. Observed 2026-08-02: `brace-expansion@<=5.0.7` sat in `Pending Status Checks` on the portal, held by the quarantine. ## The fix A `packageRules` entry matching the override mechanism in every shape it takes. npm and yarn `overrides` and `resolutions`. pnpm's `pnpm.overrides` in `package.json`. `pnpm-workspace.overrides` in `pnpm-workspace.yaml`. ### Two things worth flagging The pnpm-workspace depType is `pnpm-workspace.overrides`, not `pnpm.overrides`. I checked the npm manager docs rather than inferring it from the `package.json` field name. Inferring would have been wrong. This matters here: a depType that matches nothing fails silently and looks identical to a rule that works. That is the same class of hole this PR closes. No validator catches it either, since depTypes are free-form strings. `schedule` is needed as well as `minimumReleaseAge`. The issue proposed only the release age. The global schedule is `before 6am on monday`. Zeroing the quarantine alone would still leave the PR waiting for the weekly window. That misses the issue's own acceptance criterion, "on the run following its upstream release", by up to six days. Both are set now, matching how `vulnerabilityAlerts` already does it. ## Trade-off An override bump now skips the supply-chain quarantine even when the bump is not security work. That is a real loss. The quarantine exists to avoid pulling a freshly published compromised version. It is still the better side of the trade. Overrides are rare, hand-written and reviewed, so the exposure is narrow. The alternative is leaving a known vulnerability pinned for three extra days. The reasoning is recorded in the rule's `description`. Say the word if you would rather scope this to `pnpm-workspace.overrides` only. Narrowing it is a one-line change. ## Verification Validated with `renovate-config-validator` pinned to the deployed major (43.288.0), per #331 and the false-positive problem recorded in #256: ``` INFO: Config validated successfully against 1 file(s) ``` That result is not vacuous. With a deliberately typo'd key injected, the same command fails: ``` ERROR: Found errors in configuration "message": "Invalid configuration option: packageRules[1].minimumReleaseAgeTYPO" ``` ## Acceptance #331 asks that a security override bump appears as a PR on the run following its upstream release. The next `serialize-javascript@<=7.0.2` bump to 7.1.0, already pending on the portal's dashboard, is the natural first observation.
supernaut lade till 1 incheckning 2026-08-16 11:28:32 +00:00
fix(renovate): give hand-written security overrides the fast path
Alla kontroller lyckades
ci / ci (pull_request) Successful in 12s
f342d6becd
The preset exempts security fixes from the quarantine and the schedule, but
that exemption lives under vulnerabilityAlerts, which reaches only updates
Renovate itself classifies as alerts. A vulnerability remediated by hand as a
package-manager override is an ordinary dependency to Renovate, so it fell
under the global minimumReleaseAge of 3 days. Observed 2026-08-02:
brace-expansion@<=5.0.7 sat in Pending Status Checks on the portal, held by the
quarantine.

Adds a packageRules entry matching the override mechanism in every shape it
takes: npm/yarn overrides and resolutions, pnpm.overrides in package.json, and
pnpm-workspace.overrides in pnpm-workspace.yaml.

The depType for pnpm-workspace.yaml is pnpm-workspace.overrides, NOT
pnpm.overrides. Verified against the npm manager docs rather than inferred: a
depType that matches nothing fails silently and is indistinguishable from a
rule that works, which is the same class of hole this commit closes.

Sets schedule alongside minimumReleaseAge. The issue proposed only the release
age, but zeroing that alone still leaves the PR waiting for the weekly Monday
window, which misses the acceptance criterion ("on the run following its
upstream release") by up to six days.

Trade-off recorded in the rule's description: an override bump now skips the
supply-chain quarantine even when it is not itself security work. Overrides are
rare, hand-written and reviewed, so that is a smaller exposure than leaving a
known vulnerability pinned for three extra days.
supernaut sammanfogade incheckning e17f24dc7a till main 2026-08-16 13:36:49 +00:00
supernaut tog bort grenen fix/override-security-fast-path 2026-08-16 13:36:49 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-docs!85
Ingen beskrivning angiven.