fix(renovate): give hand-written security overrides the fast path #85
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-docs!85
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/override-security-fast-path"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Closes bitborg/bitborg-infra#331.
The hole
The preset's stated intent is that a security fix is never delayed by a global setting. That
exemption lives under
vulnerabilityAlerts. It reaches only updates Renovate itself classifies asalerts.
A vulnerability remediated by hand as a package-manager override is an ordinary dependency to
Renovate. So it fell under the global
minimumReleaseAge: "3 days". Observed 2026-08-02:brace-expansion@<=5.0.7sat inPending Status Checkson the portal, held by the quarantine.The fix
A
packageRulesentry matching the override mechanism in every shape it takes. npm and yarnoverridesandresolutions. pnpm'spnpm.overridesinpackage.json.pnpm-workspace.overridesinpnpm-workspace.yaml.Two things worth flagging
The pnpm-workspace depType is
pnpm-workspace.overrides, notpnpm.overrides. I checked the npmmanager docs rather than inferring it from the
package.jsonfield name. Inferring would have beenwrong. This matters here: a depType that matches nothing fails silently and looks identical to a
rule that works. That is the same class of hole this PR closes. No validator catches it either,
since depTypes are free-form strings.
scheduleis needed as well asminimumReleaseAge. The issue proposed only the release age. Theglobal schedule is
before 6am on monday. Zeroing the quarantine alone would still leave the PRwaiting for the weekly window. That misses the issue's own acceptance criterion, "on the run
following its upstream release", by up to six days. Both are set now, matching how
vulnerabilityAlertsalready does it.Trade-off
An override bump now skips the supply-chain quarantine even when the bump is not security work.
That is a real loss. The quarantine exists to avoid pulling a freshly published compromised
version.
It is still the better side of the trade. Overrides are rare, hand-written and reviewed, so the
exposure is narrow. The alternative is leaving a known vulnerability pinned for three extra days.
The reasoning is recorded in the rule's
description.Say the word if you would rather scope this to
pnpm-workspace.overridesonly. Narrowing it is aone-line change.
Verification
Validated with
renovate-config-validatorpinned to the deployed major (43.288.0), per #331 andthe false-positive problem recorded in #256:
That result is not vacuous. With a deliberately typo'd key injected, the same command fails:
Acceptance
#331 asks that a security override bump appears as a PR on the run following its upstream release.
The next
serialize-javascript@<=7.0.2bump to 7.1.0, already pending on the portal's dashboard,is the natural first observation.
The preset exempts security fixes from the quarantine and the schedule, but that exemption lives under vulnerabilityAlerts, which reaches only updates Renovate itself classifies as alerts. A vulnerability remediated by hand as a package-manager override is an ordinary dependency to Renovate, so it fell under the global minimumReleaseAge of 3 days. Observed 2026-08-02: brace-expansion@<=5.0.7 sat in Pending Status Checks on the portal, held by the quarantine. Adds a packageRules entry matching the override mechanism in every shape it takes: npm/yarn overrides and resolutions, pnpm.overrides in package.json, and pnpm-workspace.overrides in pnpm-workspace.yaml. The depType for pnpm-workspace.yaml is pnpm-workspace.overrides, NOT pnpm.overrides. Verified against the npm manager docs rather than inferred: a depType that matches nothing fails silently and is indistinguishable from a rule that works, which is the same class of hole this commit closes. Sets schedule alongside minimumReleaseAge. The issue proposed only the release age, but zeroing that alone still leaves the PR waiting for the weekly Monday window, which misses the acceptance criterion ("on the run following its upstream release") by up to six days. Trade-off recorded in the rule's description: an override bump now skips the supply-chain quarantine even when it is not itself security work. Overrides are rare, hand-written and reviewed, so that is a smaller exposure than leaving a known vulnerability pinned for three extra days.