-
Notifications
You must be signed in to change notification settings - Fork 2
Expand file tree
/
Copy pathrenovate.json5
More file actions
124 lines (117 loc) · 6.01 KB
/
Copy pathrenovate.json5
File metadata and controls
124 lines (117 loc) · 6.01 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
{
$schema: "https://docs.renovatebot.com/renovate-schema.json",
extends: [
"config:recommended",
":semanticCommits",
// Refresh Cargo.lock (transitive deps) once a week, independent of any
// direct dependency bump.
":maintainLockFilesWeekly",
],
// Let a release sit for a few days before we pick it up — filters out the
// "published, then yanked/hotfixed an hour later" case.
minimumReleaseAge: "3 days",
// Nothing inside the vendored C checkouts is ours to update — only the
// submodule pointers themselves (see below).
ignorePaths: ["crates/ringo-core/vendor/**"],
// The Nix workflow pushes the flake.lock relock onto Renovate's own branches.
// Without this, Renovate reads that commit as a human editing its PR, stops
// touching the branch entirely and posts a "rebasing is not possible" comment
// — observed on #82: `branch.isModified(): "true"` / `PR has been edited`.
// A stalled PR would then never pick up the next upstream release.
gitIgnoredAuthors: ["41898282+github-actions[bot]@users.noreply.github.com"],
// .gitmodules pins re/baresip to upstream release tags via `branch = vX.Y.Z`,
// which this manager resolves against tags — so we get release bumps, not
// default-branch HEAD.
"git-submodules": { enabled: true },
// Off, and the reason is worth writing down because the manager looks like it
// would solve the flake.lock problem — it does shell out to `nix flake update`.
// The catch is upstream in its extract step, which is explicit about it:
//
// // if rev is set, the flake contains a digest and can be updated directly
// // otherwise set lockedVersion so it is updated during lock file maintenance
//
// Measured against this repo with `renovate --platform=local --dry-run=lookup`:
// - tag-pinned (what we have): re/baresip come back with `lockedVersion` and
// `updates: []` — no digest, no tag, nothing, even with v4.10.0 released.
// - SHA-pinned: it offers digest updates to baresip 934338e9, which is
// `main`, not the v4.10.0 tag at a1542aed. Unreleased C is worse than a
// stale release behind a bindgen wrapper.
// - both at once: Nix refuses — "contains both a commit hash and a
// branch/tag name".
//
// The custom manager below cannot close the gap either: updateArtifacts is
// dispatched per manager, and custom managers export none, so a regex hit in
// flake.nix never reaches `nix flake update`. Renovate discussion #36047 is
// the open request for tag-aware flake updates; nobody is on it.
//
// `postUpgradeTasks` is the obvious escape hatch and it is a dead end here.
// Every command must match `allowedCommands`, which the docs call "a
// global-only configuration option" — so it cannot be set from this file, and
// Mend's own list, read out of the job log for this repo, is exactly:
// ^git add --all$ ^git reset$ ^pwd$
// No amount of `installTools: { nix: {} }` gets `nix flake update` past that.
//
// So: tags stay, git-submodules drives the bumps, and
// .github/workflows/nix.yml relocks flake.lock on Renovate's PRs.
nix: { enabled: false },
customManagers: [
{
description: "flake.nix pins the same re/baresip release tags as .gitmodules — bump them together",
customType: "regex",
managerFilePatterns: ["/(^|/)flake\\.nix$/"],
matchStrings: ['url = "github:(?<depName>baresip/(?:re|baresip))/(?<currentValue>v[^"]+)"'],
datasourceTemplate: "github-tags",
},
],
packageRules: [
{
description: "Automerge non-major updates once CI passes",
matchUpdateTypes: ["minor", "patch", "digest", "pin", "pinDigest", "lockFileMaintenance"],
automerge: true,
},
{
description: "Major updates: open a PR for manual review, never automerge",
matchUpdateTypes: ["major"],
automerge: false,
},
{
description: "One PR for all non-major Rust deps — CI here is expensive (cross-compile + multi-arch Docker)",
matchManagers: ["cargo"],
matchUpdateTypes: ["minor", "patch"],
groupName: "rust dependencies (non-major)",
},
{
description: "One PR for all workflow action bumps",
matchManagers: ["github-actions"],
groupName: "github actions",
},
{
description: "typedoc-plugin-markdown peer-depends on typedoc — they must move together",
matchManagers: ["npm"],
groupName: "docs toolchain",
// `package-lock.json` is gitignored (the docs toolchain is build tooling,
// not a shipped artifact), so there is no npm lock file to refresh. Without
// this, `:maintainLockFilesWeekly` still queues a second "lock file
// maintenance" entry on the dashboard every week that can never do anything.
lockFileMaintenance: { enabled: false },
},
{
description: "re + baresip: one PR moving .gitmodules and flake.nix in lockstep; never automerged (C/ABI surface behind ringo-core's bindgen wrapper)",
matchManagers: ["git-submodules", "custom.regex"],
groupName: "baresip vendor sources",
automerge: false,
// No age gate here, and that is load-bearing rather than lax. The
// submodule side resolves through the git-refs datasource, which carries
// no release timestamp, and Renovate >=42 treats a missing timestamp as
// "not old enough" — so any minimumReleaseAge pins the submodules
// forever while flake.nix (github-tags, timestamped) bumps on schedule.
// That asymmetry ships half an update: the flake moves to the new tag,
// the C sources the cargo build compiles stay behind. These PRs are
// reviewed by hand and never automerge, so the age gate bought nothing.
minimumReleaseAge: null,
prBodyNotes: [
"`flake.lock` is relocked by the Nix workflow, which pushes the commit onto this branch — Renovate cannot do it for a tag-pinned input. Because that push comes from `GITHUB_TOKEN`, the resulting run needs **Approve workflows to run** in the merge box before the checks turn green.",
],
},
],
}