mirror of
https://github.com/go-gitea/gitea.git
synced 2026-07-26 10:41:55 +00:00
Group updates from all managers into a single `dependencies` group so monday produces one combined PR instead of one per manager, matching what is regularly done manually to reduce CI waiting time. The `gomod` and `npm` rules remain for their `postUpgradeTasks`, which run once on the combined branch. Also replace the all-day monday schedule with the `schedule:weekly` preset (monday 0-4 UTC) so updates whose `minimumReleaseAge` lapses later in the day wait for the next weekly batch instead of raising a new PR the same day, as happened in https://github.com/go-gitea/gitea/pull/38546. `vulnerabilityAlerts` and the go toolchain rule bypass the schedule as before.
124 lines
4.2 KiB
Plaintext
124 lines
4.2 KiB
Plaintext
{
|
|
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
|
"extends": [
|
|
"config:recommended",
|
|
"helpers:pinGitHubActionDigests",
|
|
"customManagers:githubActionsVersions",
|
|
"schedule:weekly", // dependency update PR on monday, vulnerabilityAlerts bypasses this
|
|
],
|
|
"configMigration": true,
|
|
"enabledManagers": ["github-actions", "gomod", "npm", "pep621", "nix", "custom.regex", "dockerfile"],
|
|
"labels": ["dependencies"],
|
|
"branchPrefix": "renovate/",
|
|
"separateMajorMinor": false, // include major updates in group PRs
|
|
"minimumReleaseAge": "5 days",
|
|
"semanticCommits": "enabled",
|
|
"osvVulnerabilityAlerts": true,
|
|
"vulnerabilityAlerts": {
|
|
"enabled": true,
|
|
"semanticCommitType": "fix", // overrides packageRules
|
|
},
|
|
"customManagers": [
|
|
{
|
|
"customType": "regex",
|
|
"managerFilePatterns": ["/(^|/)Makefile$/"],
|
|
"matchStrings": [
|
|
"[A-Z_]+_PACKAGE\\s*\\?=\\s*(?<depName>[^@\\s]+?)(?:/cmd/[^@/\\s]+)?@(?<currentValue>\\S+)\\s+# renovate: datasource=(?<datasource>\\S+)",
|
|
"[A-Z_]+_IMAGE\\s*\\?=\\s*(?<depName>[^:\\s]+):(?<currentValue>[^@\\s]+)@(?<currentDigest>sha256:[a-f0-9]+)\\s+# renovate: datasource=(?<datasource>\\S+)",
|
|
],
|
|
},
|
|
],
|
|
"packageRules": [
|
|
{
|
|
"matchPackageNames": ["*"],
|
|
"groupName": "dependencies", // single weekly PR for all dependency updates
|
|
"semanticCommitType": "chore", // dep updates are rarely fixes for gitea
|
|
},
|
|
{
|
|
"matchPackageNames": ["@mcaptcha/vanilla-glue"],
|
|
"allowedVersions": "^0.1", // breaking changes in rc versions need to be handled
|
|
},
|
|
{
|
|
"matchPackageNames": ["cropperjs"],
|
|
"allowedVersions": "^1", // need to migrate to v2 but v2 is not compatible with v1
|
|
},
|
|
{
|
|
"matchPackageNames": ["tailwindcss"],
|
|
"allowedVersions": "^3", // need to migrate
|
|
},
|
|
{
|
|
"matchPackageNames": ["@citation-js/core", "@citation-js/plugin-bibtex", "@citation-js/plugin-csl"],
|
|
"allowedVersions": "<0.8", // https://github.com/citation-js/citation-js/pull/277
|
|
},
|
|
{
|
|
"matchPackageNames": ["typescript"],
|
|
"allowedVersions": "^6", // typescript-eslint is not yet compatible with typescript 7
|
|
},
|
|
{
|
|
"matchPackageNames": ["github.com/Azure/azure-sdk-for-go/sdk/azcore"],
|
|
"allowedVersions": "<1.21.0", // v1.21.0+ uses API version unsupported by Azurite in CI
|
|
},
|
|
{
|
|
"matchPackageNames": ["github.com/Azure/azure-sdk-for-go/sdk/storage/azblob"],
|
|
"allowedVersions": "<1.6.4", // v1.6.4+ uses API version unsupported by Azurite in CI
|
|
},
|
|
{
|
|
"matchPackageNames": ["github.com/microsoft/go-mssqldb"],
|
|
"allowedVersions": "<=1.9.7", // downgraded with Azure SDK
|
|
},
|
|
{
|
|
"matchPackageNames": ["go.yaml.in/yaml/v4"],
|
|
"allowedVersions": "<4.0.0-rc.4", // rc.4 changes block scalar serialization, wait for stable release
|
|
},
|
|
{
|
|
"matchPackageNames": ["postgres"],
|
|
"allowedVersions": "/^14($|[.-])/", // pin to oldest supported major
|
|
},
|
|
{
|
|
"matchPackageNames": ["bitnamilegacy/mysql"],
|
|
"allowedVersions": "/^8\\.4($|[.-])/", // pin to oldest LTS
|
|
},
|
|
{
|
|
"matchPackageNames": ["mcr.microsoft.com/mssql/server"],
|
|
"allowedVersions": "/^2019($|[.-])/", // pin to oldest in extended support
|
|
},
|
|
{
|
|
"matchManagers": ["gomod"],
|
|
"postUpdateOptions": ["gomodUpdateImportPaths"],
|
|
"postUpgradeTasks": {
|
|
"commands": ["make tidy"],
|
|
"fileFilters": [
|
|
"go.mod",
|
|
"go.sum",
|
|
"assets/go-licenses.json",
|
|
],
|
|
"executionMode": "branch",
|
|
},
|
|
},
|
|
{
|
|
"matchManagers": ["gomod"],
|
|
"matchDepNames": ["go"],
|
|
"matchDepTypes": ["golang"],
|
|
"rangeStrategy": "bump",
|
|
"schedule": ["at any time"],
|
|
"minimumReleaseAge": "0",
|
|
},
|
|
{
|
|
"matchManagers": ["npm"],
|
|
"postUpdateOptions": ["pnpmDedupe"],
|
|
"postUpgradeTasks": {
|
|
"commands": ["make svg", "make generate-codemirror-languages"],
|
|
"fileFilters": [
|
|
"package.json",
|
|
"pnpm-lock.yaml",
|
|
"pnpm-workspace.yaml",
|
|
"public/assets/img/svg/**",
|
|
"options/fileicon/**",
|
|
"assets/codemirror-languages.json",
|
|
],
|
|
"executionMode": "branch",
|
|
},
|
|
},
|
|
],
|
|
}
|