renovate: no Forgejo or Postgres security release can bypass the weekly schedule #446
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#446
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Related to #430, but a different claim. #430 is about updates held forever. This is about updates
held up to six days, by design, including for the git server.
The gap
A Forgejo or Postgres image security release cannot bypass the weekly schedule.
The shared preset sets
schedule: ["before 6am on monday"]globally, and exempts security work:That exemption only reaches updates Renovate itself classifies as vulnerability alerts. Both
sources of that classification are unavailable here:
them, so there are none to read.
osvVulnerabilityAlerts: true. OSV covers package ecosystems (npm, PyPI, Go, crates and so on).It has no ecosystem for a container image tag.
Forgejo and Postgres are tracked by
customManagersin this repo withdatasource=docker, matching a*_image_tagline in Ansible vars. Renovate has no vulnerability feed for that. So the update is anordinary scheduled bump, and
vulnerabilityAlertsnever applies to it.Neither this repo's
renovate.jsonnor the shared preset gives forgejo or postgres a faster schedule.The only rule naming them is the major gate, which slows them down rather than speeding them up.
Currently observable
forgejo 16.0.2is in the Dependency Dashboard's Awaiting Schedule section right now, waiting forMonday. Whether 16.0.2 carries security fixes has not been established here and should be checked
against the upstream release notes.
Why this is worth separating from #430
#430's acceptance says the outcome that matters is "a Forgejo security update reaching a reviewable
PR". Watching 16.0.2 open on Monday proves the
timestamp-requiredbug from #430 is fixed. It does notprove security updates arrive promptly, because Monday is exactly when a Monday-scheduled update would
open either way.
Two different properties, and one observation cannot distinguish them:
"Awaiting Schedule", and the dashboard now carries the
minimumReleaseAgeBehaviour=timestamp-optionalWARN.
current config.
Closing #430 on Monday is correct. It should not be read as closing this.
Options, not yet chosen
packageRulematchingcodeberg.org/forgejo/forgejoanddocker.io/library/postgreswith a daily rather than weeklywindow. Simple, and it applies whether or not a given release is security work. Costs a review of
ordinary patch bumps up to six days sooner than today.
classify. Forgejo publishes release announcements; an alert on "deployed tag is behind latest" is
independent of Renovate entirely and would also cover the case where Renovate is broken.
it stops looking like an oversight. Weakest option, but honest, and better than the current state
where the config reads as though
vulnerabilityAlertscovers this.Option 1 is the cheapest real improvement; option 2 is the one that does not depend on Renovate being
healthy. They are complementary rather than alternatives.
Definition of done
platform=local+dry-run=fullAND a control runwithout the rule, since a
matchDepNamesmatching nothing looks identical to a rule that worksvulnerabilityAlertsin the shared preset carries a note that it cannot reach docker-tagdependencies, so the next reader does not assume it does