255 lines
10 KiB
JSON
255 lines
10 KiB
JSON
{
|
|
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
|
"extends": ["config:recommended", ":dependencyDashboard"],
|
|
"enabledManagers": ["dockerfile", "docker-compose", "kubernetes", "helm-values", "custom.regex"],
|
|
"onboarding": false,
|
|
"requireConfig": "optional",
|
|
"autodiscover": false,
|
|
"dependencyDashboard": true,
|
|
"prCreation": "immediate",
|
|
"labels": ["dependencies", "automated"],
|
|
"docker-compose": {
|
|
"managerFilePatterns": ["renovate/renovate-compose.yaml"]
|
|
},
|
|
"helm-values": {
|
|
"managerFilePatterns": ["/k8s/.+values\\.ya?ml$/"]
|
|
},
|
|
"kubernetes": {
|
|
"managerFilePatterns": ["/k8s/.+\\.ya?ml$/"]
|
|
},
|
|
"customManagers": [
|
|
{
|
|
"customType": "regex",
|
|
"description": "singlesource: playwright npm version pinned in npx command (k8s + compose)",
|
|
"managerFilePatterns": ["edu_master/k8s/playwright.yaml", "edu_master/compose.yaml"],
|
|
"matchStrings": ["playwright@(?<currentValue>\\d+\\.\\d+\\.\\d+)"],
|
|
"datasourceTemplate": "npm",
|
|
"depNameTemplate": "playwright"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "singlesource: PLAYWRIGHT_VERSION file",
|
|
"managerFilePatterns": ["edu_master/PLAYWRIGHT_VERSION"],
|
|
"matchStrings": ["^(?<currentValue>\\d+\\.\\d+\\.\\d+)(?:\\r?\\n)?$"],
|
|
"datasourceTemplate": "pypi",
|
|
"depNameTemplate": "playwright"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "singlesource: playwright Python client version pinned in Dockerfile ARG",
|
|
"managerFilePatterns": ["edu_master/webinar-checker/Dockerfile"],
|
|
"matchStrings": ["(?:^|\\n)ARG PLAYWRIGHT_VERSION=(?<currentValue>\\d+\\.\\d+\\.\\d+)(?:\\r?\\n|$)"],
|
|
"datasourceTemplate": "pypi",
|
|
"depNameTemplate": "playwright",
|
|
"versioningTemplate": "pep440"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "kube-prometheus-stack chart version pinned in the deploy workflow",
|
|
"managerFilePatterns": [".gitea/workflows/deploy-lib.sh"],
|
|
"matchStrings": ["\\|prometheus-community/kube-prometheus-stack\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
|
"datasourceTemplate": "helm",
|
|
"depNameTemplate": "kube-prometheus-stack",
|
|
"registryUrlTemplate": "https://prometheus-community.github.io/helm-charts"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "grafana/loki chart version pinned in the deploy workflow",
|
|
"managerFilePatterns": [".gitea/workflows/deploy-lib.sh"],
|
|
"matchStrings": ["\\|grafana/loki\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
|
"datasourceTemplate": "helm",
|
|
"depNameTemplate": "loki",
|
|
"registryUrlTemplate": "https://grafana.github.io/helm-charts"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "grafana/alloy chart version pinned in the deploy workflow",
|
|
"managerFilePatterns": [".gitea/workflows/deploy-lib.sh"],
|
|
"matchStrings": ["\\|grafana/alloy\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
|
"datasourceTemplate": "helm",
|
|
"depNameTemplate": "alloy",
|
|
"registryUrlTemplate": "https://grafana.github.io/helm-charts"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "actionlint version used by the ci workflow",
|
|
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
|
"matchStrings": ["(?:^|\\n)ACTIONLINT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "rhysd/actionlint"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "shellcheck version used by the ci workflow",
|
|
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
|
"matchStrings": ["(?:^|\\n)SHELLCHECK_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "koalaman/shellcheck"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "kubeconform version used by the ci workflow",
|
|
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
|
"matchStrings": ["(?:^|\\n)KUBECONFORM_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "yannh/kubeconform"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "uv version used to build the pytest venv",
|
|
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
|
"matchStrings": ["(?:^|\\n)UV_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "astral-sh/uv"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "prettier version used by the ci workflow",
|
|
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
|
"matchStrings": ["(?:^|\\n)PRETTIER_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "npm",
|
|
"depNameTemplate": "prettier"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "ruff version used by the ci workflow",
|
|
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
|
"matchStrings": ["(?:^|\\n)RUFF_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "pypi",
|
|
"depNameTemplate": "ruff"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "pip-audit version used by the ci workflow",
|
|
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
|
"matchStrings": ["(?:^|\\n)PIP_AUDIT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "pypi",
|
|
"depNameTemplate": "pip-audit"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "yamllint version used by the ci workflow",
|
|
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
|
"matchStrings": ["(?:^|\\n)YAMLLINT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "pypi",
|
|
"depNameTemplate": "yamllint"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "hadolint version used by the ci workflow",
|
|
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
|
"matchStrings": ["(?:^|\\n)HADOLINT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "hadolint/hadolint"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "node version the ci workflow runs npm with",
|
|
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
|
"matchStrings": ["(?:^|\\n)NODE_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "node",
|
|
"depNameTemplate": "node"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "stakater/reloader chart version pinned in the deploy workflow",
|
|
"managerFilePatterns": [".gitea/workflows/deploy-lib.sh"],
|
|
"matchStrings": ["\\|stakater/reloader\\|reloader\\|(?<currentValue>[0-9.]+)\\|"],
|
|
"datasourceTemplate": "helm",
|
|
"depNameTemplate": "reloader",
|
|
"registryUrlTemplate": "https://stakater.github.io/stakater-charts"
|
|
}
|
|
],
|
|
"packageRules": [
|
|
{
|
|
"description": "Automerge ordinary digest and patch updates after successful checks; specific manual-review rules below override this.",
|
|
"matchUpdateTypes": ["digest", "patch"],
|
|
"automerge": true
|
|
},
|
|
{
|
|
"description": "Group all minor updates into one reviewable PR - placed before the specific groups below so playwright/node/renovate keep their own lockstep groups (later groupName wins)",
|
|
"matchUpdateTypes": ["minor"],
|
|
"groupName": "all minor updates",
|
|
"groupSlug": "all-minor",
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Group ordinary patch updates; the specific groups and manual-review rules below take precedence",
|
|
"matchUpdateTypes": ["patch"],
|
|
"groupName": "all patch updates",
|
|
"groupSlug": "all-patch"
|
|
},
|
|
{
|
|
"description": "Keep private homelab images unchanged",
|
|
"matchDatasources": ["docker"],
|
|
"matchPackageNames": ["/gcr\\.forust\\.xyz\\/forust\\/.+/"],
|
|
"enabled": false
|
|
},
|
|
{
|
|
"description": "singlesource playwright - use whichever version is found, keep docker+pypi+npm in sync",
|
|
"matchPackageNames": ["playwright", "mcr.microsoft.com/playwright"],
|
|
"groupName": "playwright singlesource",
|
|
"groupSlug": "playwright"
|
|
},
|
|
{
|
|
"description": "playwright must not automerge - version skew breaks the WS handshake (checker.py:1523 vs playwright.yaml:20)",
|
|
"matchPackageNames": ["playwright", "mcr.microsoft.com/playwright"],
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Renovate updates itself in lockstep across the CronJob and the Compose file",
|
|
"matchPackageNames": ["renovate/renovate"],
|
|
"groupName": "renovate self-update",
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Keep CI Node runtime updates in a separate, manually reviewed group",
|
|
"matchPackageNames": ["node"],
|
|
"groupName": "node runtime",
|
|
"groupSlug": "node",
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Helm chart bumps change PVC fields and admission behaviour, keep them reviewable",
|
|
"matchDatasources": ["helm"],
|
|
"groupName": "Helm chart {{depName}}",
|
|
"groupSlug": "helm-{{depName}}",
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Require approval for major upgrades",
|
|
"matchUpdateTypes": ["major"],
|
|
"dependencyDashboardApproval": true,
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Python Y-bumps break compat (3.11->3.12->3.13->3.14) - keep the base image out of the shared minor/patch groups, review every bump separately. Placed last so its groupName wins.",
|
|
"matchDatasources": ["docker"],
|
|
"matchPackageNames": ["python"],
|
|
"groupName": "python base image",
|
|
"groupSlug": "python",
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Rolling/floating tags (streaming stack, nextcloud beta, kubectl latest) - never automerge, every bump is a manual review. Placed last so automerge:false wins over the shared digest/patch rule.",
|
|
"matchDatasources": ["docker"],
|
|
"matchPackageNames": [
|
|
"lscr.io/linuxserver/jellyfin",
|
|
"lscr.io/linuxserver/qbittorrent",
|
|
"lscr.io/linuxserver/sonarr",
|
|
"lscr.io/linuxserver/radarr",
|
|
"lscr.io/linuxserver/prowlarr",
|
|
"lscr.io/linuxserver/bazarr",
|
|
"ghcr.io/seerr-team/seerr",
|
|
"fallenbagel/jellyseerr",
|
|
"ghcr.io/lampac-nextgen/lampac",
|
|
"ghcr.io/nextcloud-releases/all-in-one",
|
|
"alpine/kubectl"
|
|
],
|
|
"groupName": "floating images - manual",
|
|
"groupSlug": "floating-manual",
|
|
"automerge": false
|
|
}
|
|
]
|
|
}
|