ci: security overrides are delayed by the Renovate release-age quarantine #331

Stängd
öppnade 2026-08-02 12:30:47 +00:00 av supernaut · 0 kommentarer
Ägare

The shared preset (bitborg-docs/default.json) deliberately exempts security fixes from the
quarantine and the schedule:

"vulnerabilityAlerts": { "minimumReleaseAge": "0 days", "schedule": ["at any time"] }

That exemption only applies to updates Renovate itself classifies as vulnerability alerts. A
vulnerability remediated by hand as a package-manager override (the dependency@<=x.y.z shape in
pnpm-workspace.yaml) is an ordinary dependency as far as Renovate is concerned, so it falls under
the global minimumReleaseAge: "3 days" instead.

Observed on 2026-08-02: brace-expansion@<=5.0.7 → v5.0.9 sat in Pending Status Checks on the web
portal's Dependency Dashboard, held by the release-age quarantine. The preset's stated intent is that
security fixes are never delayed by a global setting — this is a hole in that intent.

Proposed fix — a packageRules entry in bitborg-docs/default.json matching the override shape
and pinning minimumReleaseAge to "0 days", so hand-written security overrides get the same
fast path as detected alerts. Validate with renovate-config-validator pinned to the deployed
major (43)
— npx resolves an older version that produces false positives against config already
live on main (see PR #256).

Acceptance: a security override bump appears as a PR on the run following its upstream release,
not three days later.

The shared preset (`bitborg-docs/default.json`) deliberately exempts security fixes from the quarantine and the schedule: ```json "vulnerabilityAlerts": { "minimumReleaseAge": "0 days", "schedule": ["at any time"] } ``` That exemption only applies to updates Renovate itself classifies as vulnerability alerts. A vulnerability remediated by hand as a package-manager **override** (the `dependency@<=x.y.z` shape in `pnpm-workspace.yaml`) is an ordinary dependency as far as Renovate is concerned, so it falls under the global `minimumReleaseAge: "3 days"` instead. Observed on 2026-08-02: `brace-expansion@<=5.0.7 → v5.0.9` sat in `Pending Status Checks` on the web portal's Dependency Dashboard, held by the release-age quarantine. The preset's stated intent is that security fixes are never delayed by a global setting — this is a hole in that intent. **Proposed fix** — a `packageRules` entry in `bitborg-docs/default.json` matching the override shape and pinning `minimumReleaseAge` to `"0 days"`, so hand-written security overrides get the same fast path as detected alerts. Validate with `renovate-config-validator` **pinned to the deployed major (43)** — `npx` resolves an older version that produces false positives against config already live on `main` (see PR #256). **Acceptance:** a security override bump appears as a PR on the run following its upstream release, not three days later.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#331
Ingen beskrivning angiven.