ci: security overrides are delayed by the Renovate release-age quarantine #331
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#331
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
The shared preset (
bitborg-docs/default.json) deliberately exempts security fixes from thequarantine and the schedule:
That exemption only applies to updates Renovate itself classifies as vulnerability alerts. A
vulnerability remediated by hand as a package-manager override (the
dependency@<=x.y.zshape inpnpm-workspace.yaml) is an ordinary dependency as far as Renovate is concerned, so it falls underthe global
minimumReleaseAge: "3 days"instead.Observed on 2026-08-02:
brace-expansion@<=5.0.7 → v5.0.9sat inPending Status Checkson the webportal's Dependency Dashboard, held by the release-age quarantine. The preset's stated intent is that
security fixes are never delayed by a global setting — this is a hole in that intent.
Proposed fix — a
packageRulesentry inbitborg-docs/default.jsonmatching the override shapeand pinning
minimumReleaseAgeto"0 days", so hand-written security overrides get the samefast path as detected alerts. Validate with
renovate-config-validatorpinned to the deployedmajor (43) —
npxresolves an older version that produces false positives against config alreadylive on
main(see PR #256).Acceptance: a security override bump appears as a PR on the run following its upstream release,
not three days later.