ci: adopt the shared renovate preset #108

Sammanfogat
supernaut sammanfogade 2 incheckningar från ci/renovate-config-tweak in i main 2026-07-30 15:16:37 +00:00
Ägare

Replaces this repo's copy of the Renovate config with a single extends:

{
  "$schema": "https://docs.renovatebot.com/renovate-schema.json",
  "extends": ["local>gitborg/gitborg-docs"]
}

Seven repos held near-identical renovate.json files, hand-synced and already drifted
(lockFileMaintenance was in four of them, missing from three). The shared configuration now lives in
bitborg-docs/default.json — Renovate resolves an unnamed preset to default.json. A policy change
becomes one PR instead of seven.

Behaviour changes that come with it

  • Majors are gated, not disabled. major: {enabled: false} stopped majors being created at all,
    so they never reached the Dependency Dashboard either — we would simply stop being told a new major
    exists. Now major: {dependencyDashboardApproval: true}: no unsolicited PRs, but the update stays
    visible for deliberate opt-in, and remains available to security remediation.
  • Labels use the shared vocabulary. dependencies and security are not in
    contributing/issue-tracking.md and do not exist on the repos, so Renovate dropped them silently.
    Now type/chore, plus area/security for vulnerability PRs.
  • minimumReleaseAge: "3 days" quarantines fresh releases against the compromised-publish
    pattern (principle 4). Security fixes bypass it — vulnerabilityAlerts pins the age to zero
    explicitly, so changing the global value can never delay one.

Verification

Validated with renovate-config-validator against Renovate 43, the version the services host
deploys. Note an older validator (37.x, which is what npx resolves by default) reports false
positives on current config options.

Merge order

Depends on the bitborg-docs PR that adds the preset — merge that first. Until it lands this repo
points at a preset that does not exist, and a failed local> resolution means no Renovate config at
all. Preset resolution can only be exercised on a real Renovate run; the validator has no platform
access.

Replaces this repo's copy of the Renovate config with a single `extends`: ```json { "$schema": "https://docs.renovatebot.com/renovate-schema.json", "extends": ["local>gitborg/gitborg-docs"] } ``` Seven repos held near-identical `renovate.json` files, hand-synced and already drifted (`lockFileMaintenance` was in four of them, missing from three). The shared configuration now lives in `bitborg-docs/default.json` — Renovate resolves an unnamed preset to `default.json`. A policy change becomes one PR instead of seven. ## Behaviour changes that come with it - **Majors are gated, not disabled.** `major: {enabled: false}` stopped majors being created at all, so they never reached the Dependency Dashboard either — we would simply stop being told a new major exists. Now `major: {dependencyDashboardApproval: true}`: no unsolicited PRs, but the update stays visible for deliberate opt-in, and remains available to security remediation. - **Labels use the shared vocabulary.** `dependencies` and `security` are not in `contributing/issue-tracking.md` and do not exist on the repos, so Renovate dropped them silently. Now `type/chore`, plus `area/security` for vulnerability PRs. - **`minimumReleaseAge: "3 days"`** quarantines fresh releases against the compromised-publish pattern (principle 4). Security fixes bypass it — `vulnerabilityAlerts` pins the age to zero explicitly, so changing the global value can never delay one. ## Verification Validated with `renovate-config-validator` against **Renovate 43**, the version the services host deploys. Note an older validator (37.x, which is what `npx` resolves by default) reports false positives on current config options. ## Merge order **Depends on the bitborg-docs PR that adds the preset — merge that first.** Until it lands this repo points at a preset that does not exist, and a failed `local>` resolution means no Renovate config at all. Preset resolution can only be exercised on a real Renovate run; the validator has no platform access.
supernaut lade till 2 incheckningar 2026-07-30 15:13:05 +00:00
ci: adopt the shared renovate preset
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m25s
4cb686a72e
Replaces this repo's copy of the renovate config with
`extends: ["local>gitborg/gitborg-docs"]`. The shared configuration now lives in
gitborg-docs/default.json — seven repos held near-identical copies that were
hand-synced and had already drifted.

Two behaviour corrections come with it: majors are gated behind Dependency
Dashboard approval rather than disabled outright (so a new major still shows up
instead of vanishing), and labels use the shared vocabulary from
contributing/issue-tracking.md — the previous `dependencies` / `security` labels
are not in it and do not exist on the repos, so Renovate dropped them silently.

Validated against Renovate 43, the version the services host runs.
supernaut sammanfogade incheckning 0ffa3ca0ad till main 2026-07-30 15:16:37 +00:00
supernaut tog bort grenen ci/renovate-config-tweak 2026-07-30 15:16:37 +00:00
supernaut refererade denna ändringsförfrågan från en incheckning 2026-07-30 15:16:38 +00:00
supernaut refererade denna ändringsförfrågan från en incheckning 2026-08-03 09:41:50 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-web!108
Ingen beskrivning angiven.