chore(renovate): track tool version pins in scripts #530

Öppen
supernaut vill sammanfoga 2 incheckningar från s[2]s in i main
Ägare

What

  1. A third regex customManager in renovate.json reads # renovate: annotations above *_VERSION= lines in scripts/*.sh. Annotated: runner, tofu, node, gitleaks, ruff (bake script and wrapper share one depName, so one PR moves both), shellcheck.
  2. check-renovate-annotations.py now also checks scripts/*.sh (unannotated pin, annotation not matched) and runs in CI when scripts/ changes.
  3. CI runs scripts/tofu-apply.sh --self-test when scripts/ changes. It uses a temp repo and needs no credentials.

Why

The script pins were outside every manager, so no PR was ever opened for them. The tofu-apply self-test covers the only rollback point for local state and was never run.

Tested

  • Annotation check: OK, 29 tracked, 4 exempt. Negative controls (remove an annotation, insert a comment between) both fail.
  • Regexes applied to every pin: 7 of 7 captured with expected depName and currentValue.
  • Renovate 43 local dry-run (platform=local, dry-run=full, schedule overridden, shared preset not loaded): all 7 extracted. forgejo/runner, node and ruff show updates. The three github-releases pins skip with github-token-required (no token locally only).
  • --self-test: 6/6 pass.
  • prettier, markdownlint, ruff 0.16.1 pass. shellcheck passes with the local 0.11 (podman cannot mount /Volumes).

Open questions

  • SHELLCHECK_VERSION is pinned to the Debian trixie version that the runner bakes via apt. A bump PR makes CI use the container and diverge from the baked binary. Accept, or exempt it?
  • NODE_VERSION in the bake script is 24.18.0 while volta.node is 24.21.0. Renovate will bump it and group it with the toolchain rule (depName node). A re-bake is needed afterwards.
  • Not done: replacing _mini_yaml in scripts/openstack-cost.py with PyYAML. The default python3 on the operator machine (Homebrew) has no PyYAML, only the openstack and ansible venvs do, so the fallback is still needed. No other hand-rolled YAML parser in scripts/ (load-web-image.sh reads one-line scalars with sed).
## What 1. A third regex customManager in `renovate.json` reads `# renovate:` annotations above `*_VERSION=` lines in `scripts/*.sh`. Annotated: runner, tofu, node, gitleaks, ruff (bake script and wrapper share one depName, so one PR moves both), shellcheck. 2. `check-renovate-annotations.py` now also checks `scripts/*.sh` (unannotated pin, annotation not matched) and runs in CI when `scripts/` changes. 3. CI runs `scripts/tofu-apply.sh --self-test` when `scripts/` changes. It uses a temp repo and needs no credentials. ## Why The script pins were outside every manager, so no PR was ever opened for them. The tofu-apply self-test covers the only rollback point for local state and was never run. ## Tested - Annotation check: OK, 29 tracked, 4 exempt. Negative controls (remove an annotation, insert a comment between) both fail. - Regexes applied to every pin: 7 of 7 captured with expected depName and currentValue. - Renovate 43 local dry-run (platform=local, dry-run=full, schedule overridden, shared preset not loaded): all 7 extracted. forgejo/runner, node and ruff show updates. The three github-releases pins skip with `github-token-required` (no token locally only). - `--self-test`: 6/6 pass. - prettier, markdownlint, ruff 0.16.1 pass. shellcheck passes with the local 0.11 (podman cannot mount /Volumes). ## Open questions - `SHELLCHECK_VERSION` is pinned to the Debian trixie version that the runner bakes via apt. A bump PR makes CI use the container and diverge from the baked binary. Accept, or exempt it? - `NODE_VERSION` in the bake script is 24.18.0 while `volta.node` is 24.21.0. Renovate will bump it and group it with the toolchain rule (depName `node`). A re-bake is needed afterwards. - Not done: replacing `_mini_yaml` in `scripts/openstack-cost.py` with PyYAML. The default `python3` on the operator machine (Homebrew) has no PyYAML, only the openstack and ansible venvs do, so the fallback is still needed. No other hand-rolled YAML parser in scripts/ (`load-web-image.sh` reads one-line scalars with sed).
supernaut lade till 2 incheckningar 2026-10-03 00:10:03 +00:00
The pins in bake-runner-image.sh, ruff.sh and shellcheck.sh sat outside
every customManager, so nothing told us about new runner, tofu, node,
gitleaks, ruff or shellcheck releases. A third regex manager reads a
`# renovate:` annotation above each `*_VERSION=` line. The ruff pin in
the wrapper and the bake script share one depName, so they move in one
PR.

check-renovate-annotations.py now covers scripts/*.sh (unannotated pin,
annotation not matched) and runs when scripts/ changes.

Checked locally with Renovate (platform=local, dry-run=full): all seven
pins are extracted. The github-releases ones skip for lack of a token
in that run only.
ci: run the tofu-apply self-test
Alla kontroller lyckades
ci / ci (pull_request) Successful in 2m28s
c8c314abda
The self-test covers snapshot, prune and restore of the OpenTofu state
files, which is the only rollback point for local state. It was never
run by CI. It works in a temp repo and needs no credentials, so run it
whenever scripts/ changes.
supernaut schemalade den här ändringsförfrågan för automatisk sammanfogning när alla kontroller lyckas 2026-10-03 00:10:19 +00:00
Alla kontroller lyckades
ci / ci (pull_request) Successful in 2m28s
Obligatorisk
Detaljer
den här ändringsförfrågan är blockerad eftersom den är föråldrad.
Den här grenen är föråldrad gentemot basgrenen
Du är inte behörig att sammanfoga den här ändringsförfrågan.
Visa kommandoradsinstruktioner

Checka ut

Checka ut en ny gren från din projektkatalog och testa ändringarna.
git fetch -u origin chore/renovate-script-pins:chore/renovate-script-pins
git switch chore/renovate-script-pins
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!530
Ingen beskrivning angiven.