prettier, ruff, yamllint and hadolint were the only CI tools still called bare, straight off whatever the runner happened to have installed. Pin them in tool-versions.env like the other three and install them the same way, so the versions Renovate moves are the versions CI runs. Each pinned version equals what is already on the runner, so this changes what CI does not at all today. It changes what CI does on a rebuilt runner: the pinned one gets installed over the drift. The four need four different mechanisms, which is why this is not one pattern: hadolint a bare binary per platform, like actionlint ruff, yamllint PyPI wheels, unpacked by uv prettier an npm tarball, unpacked by tar prettier is the awkward one. Its entry point requires ../package.json relative to its own real path, so copying the single file out -- which is what every other installer here does -- yields a module-not-found at the first run. It keeps its package directory in a versioned one next to a relative symlink, and the tarball ships bin/ without the exec bit, so that needs chmod too. hadolint's release names one platform uname-style and the other Go-style (x86_64 but arm64), which 404s on the first architecture if you assume otherwise. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
178 lines
7.2 KiB
JSON
178 lines
7.2 KiB
JSON
{
|
|
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
|
"extends": ["config:recommended", ":dependencyDashboard"],
|
|
"enabledManagers": ["dockerfile", "docker-compose", "kubernetes", "helm-values", "custom.regex"],
|
|
"onboarding": false,
|
|
"requireConfig": "optional",
|
|
"autodiscover": false,
|
|
"dependencyDashboard": true,
|
|
"prCreation": "immediate",
|
|
"labels": ["dependencies", "automated"],
|
|
"helm-values": {
|
|
"managerFilePatterns": ["/k8s/.+values\\.ya?ml$/"]
|
|
},
|
|
"kubernetes": {
|
|
"managerFilePatterns": ["/k8s/.+\\.ya?ml$/"]
|
|
},
|
|
"customManagers": [
|
|
{
|
|
"customType": "regex",
|
|
"description": "singlesource: playwright npm version pinned in npx command (k8s + compose)",
|
|
"managerFilePatterns": ["^edu_master/k8s/playwright\\.yaml$", "^edu_master/compose\\.yaml$"],
|
|
"matchStrings": ["playwright@(?<currentValue>\\d+\\.\\d+\\.\\d+)"],
|
|
"datasourceTemplate": "npm",
|
|
"depNameTemplate": "playwright"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "singlesource: PLAYWRIGHT_VERSION file",
|
|
"managerFilePatterns": ["^edu_master/PLAYWRIGHT_VERSION$"],
|
|
"matchStrings": ["^(?<currentValue>\\d+\\.\\d+\\.\\d+)$"],
|
|
"datasourceTemplate": "pypi",
|
|
"depNameTemplate": "playwright"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "kube-prometheus-stack chart version pinned in the deploy workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
|
"matchStrings": ["\\|prometheus-community/kube-prometheus-stack\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
|
"datasourceTemplate": "helm",
|
|
"depNameTemplate": "kube-prometheus-stack",
|
|
"registryUrlTemplate": "https://prometheus-community.github.io/helm-charts"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "grafana/loki chart version pinned in the deploy workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
|
"matchStrings": ["\\|grafana/loki\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
|
"datasourceTemplate": "helm",
|
|
"depNameTemplate": "loki",
|
|
"registryUrlTemplate": "https://grafana.github.io/helm-charts"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "grafana/alloy chart version pinned in the deploy workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
|
"matchStrings": ["\\|grafana/alloy\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
|
"datasourceTemplate": "helm",
|
|
"depNameTemplate": "alloy",
|
|
"registryUrlTemplate": "https://grafana.github.io/helm-charts"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "actionlint version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)ACTIONLINT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "rhysd/actionlint"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "shellcheck version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)SHELLCHECK_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "koalaman/shellcheck"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "kubeconform version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)KUBECONFORM_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "yannh/kubeconform"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "uv version used to build the pytest venv",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)UV_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "astral-sh/uv"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "prettier version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)PRETTIER_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "npm",
|
|
"depNameTemplate": "prettier"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "ruff version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)RUFF_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "pypi",
|
|
"depNameTemplate": "ruff"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "yamllint version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)YAMLLINT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "pypi",
|
|
"depNameTemplate": "yamllint"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "hadolint version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)HADOLINT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "hadolint/hadolint"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "stakater/reloader chart version pinned in the deploy workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
|
"matchStrings": ["\\|stakater/reloader\\|reloader\\|(?<currentValue>[0-9.]+)\\|"],
|
|
"datasourceTemplate": "helm",
|
|
"depNameTemplate": "reloader",
|
|
"registryUrlTemplate": "https://stakater.github.io/stakater-charts"
|
|
}
|
|
],
|
|
"packageRules": [
|
|
{
|
|
"description": "Keep private homelab images unchanged",
|
|
"matchDatasources": ["docker"],
|
|
"matchPackageNames": ["/gcr\\.forust\\.xyz\\/forust\\/.+/"],
|
|
"enabled": false
|
|
},
|
|
{
|
|
"description": "singlesource playwright - use whichever version is found, keep docker+pypi+npm in sync",
|
|
"matchPackageNames": ["playwright", "mcr.microsoft.com/playwright"],
|
|
"groupName": "playwright singlesource",
|
|
"groupSlug": "playwright"
|
|
},
|
|
{
|
|
"description": "playwright must not automerge - version skew breaks the WS handshake (checker.py:1523 vs playwright.yaml:20)",
|
|
"matchPackageNames": ["playwright", "mcr.microsoft.com/playwright"],
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Renovate updates itself in lockstep across the CronJob and the Compose file",
|
|
"matchPackageNames": ["renovate/renovate"],
|
|
"groupName": "renovate self-update",
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Helm chart bumps change PVC fields and admission behaviour, keep them reviewable",
|
|
"matchDatasources": ["helm"],
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Require approval for major upgrades",
|
|
"matchUpdateTypes": ["major"],
|
|
"dependencyDashboardApproval": true,
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Group container patch updates",
|
|
"matchDatasources": ["docker"],
|
|
"matchUpdateTypes": ["patch"],
|
|
"groupName": "container patch updates"
|
|
}
|
|
]
|
|
}
|