Two things, both about not finding out late. No workflow declared `permissions`, so all eighteen jobs across the four workflows ran on a token with the default full repository scope. Every one of them only checks out code, and deploy reaches the cluster over SSH with the deploy key, and Renovate writes through its own bot PAT rather than the Actions token. So `contents: read` is all any of them needed. The panel image ships 15 known advisories and nothing was looking. Add a scan-deps job that fails on anything new, and record the eight current ones by ID in the workflow. It is a list rather than a baseline count so that the diff that accepts an advisory says so in words, and it lives in our workflow instead of the package manifest so a subtree sync from forust/userbot cannot quietly widen the exemption. Both halves were checked to fail on a regression, not just to pass today: removing one --ignore-vuln turns the Python step red, and dropping --audit-level to moderate turns the npm one red on the devalue advisory. npm audits production dependencies only. All seven findings in the full tree are build- or test-time: the esbuild advisory needs a vite dev server exposed to the internet, and nanoid's infinite loop needs a custom generator called with size 0, which postcss does not do. None are in the 91 kB bundle the panel serves, so failing on them would be noise that trains people to ignore the job. The starlette entries are the reason the job is not "fail on everything": fastapi 0.115.12 pins starlette<0.47.0 and the last four fixes need 0.49.1 through 1.3.1, so clearing them is a jump to fastapi 0.141.x and is upstream's call, not a drive-by. Four of the seven are reachable in principle, which the comment on the job sets out. The panel answers only on userbot.workstation.internal with no public route, which is what keeps those four from being an internet-facing DoS. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
197 lines
8.5 KiB
YAML
197 lines
8.5 KiB
YAML
# GENERATED FILE - do not edit by hand.
|
|
# Source: renovate/renovate.json
|
|
# Regenerate: .gitea/workflows/sync-renovate-configmap.sh
|
|
# Verify: .gitea/workflows/sync-renovate-configmap.sh --check
|
|
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: renovate-config
|
|
namespace: renovate
|
|
data:
|
|
renovate.json: |
|
|
{
|
|
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
|
"extends": ["config:recommended", ":dependencyDashboard"],
|
|
"enabledManagers": ["dockerfile", "docker-compose", "kubernetes", "helm-values", "custom.regex"],
|
|
"onboarding": false,
|
|
"requireConfig": "optional",
|
|
"autodiscover": false,
|
|
"dependencyDashboard": true,
|
|
"prCreation": "immediate",
|
|
"labels": ["dependencies", "automated"],
|
|
"helm-values": {
|
|
"managerFilePatterns": ["/k8s/.+values\\.ya?ml$/"]
|
|
},
|
|
"kubernetes": {
|
|
"managerFilePatterns": ["/k8s/.+\\.ya?ml$/"]
|
|
},
|
|
"customManagers": [
|
|
{
|
|
"customType": "regex",
|
|
"description": "singlesource: playwright npm version pinned in npx command (k8s + compose)",
|
|
"managerFilePatterns": ["^edu_master/k8s/playwright\\.yaml$", "^edu_master/compose\\.yaml$"],
|
|
"matchStrings": ["playwright@(?<currentValue>\\d+\\.\\d+\\.\\d+)"],
|
|
"datasourceTemplate": "npm",
|
|
"depNameTemplate": "playwright"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "singlesource: PLAYWRIGHT_VERSION file",
|
|
"managerFilePatterns": ["^edu_master/PLAYWRIGHT_VERSION$"],
|
|
"matchStrings": ["^(?<currentValue>\\d+\\.\\d+\\.\\d+)$"],
|
|
"datasourceTemplate": "pypi",
|
|
"depNameTemplate": "playwright"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "kube-prometheus-stack chart version pinned in the deploy workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
|
"matchStrings": ["\\|prometheus-community/kube-prometheus-stack\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
|
"datasourceTemplate": "helm",
|
|
"depNameTemplate": "kube-prometheus-stack",
|
|
"registryUrlTemplate": "https://prometheus-community.github.io/helm-charts"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "grafana/loki chart version pinned in the deploy workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
|
"matchStrings": ["\\|grafana/loki\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
|
"datasourceTemplate": "helm",
|
|
"depNameTemplate": "loki",
|
|
"registryUrlTemplate": "https://grafana.github.io/helm-charts"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "grafana/alloy chart version pinned in the deploy workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
|
"matchStrings": ["\\|grafana/alloy\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
|
"datasourceTemplate": "helm",
|
|
"depNameTemplate": "alloy",
|
|
"registryUrlTemplate": "https://grafana.github.io/helm-charts"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "actionlint version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)ACTIONLINT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "rhysd/actionlint"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "shellcheck version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)SHELLCHECK_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "koalaman/shellcheck"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "kubeconform version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)KUBECONFORM_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "yannh/kubeconform"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "uv version used to build the pytest venv",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)UV_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "astral-sh/uv"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "prettier version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)PRETTIER_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "npm",
|
|
"depNameTemplate": "prettier"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "ruff version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)RUFF_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "pypi",
|
|
"depNameTemplate": "ruff"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "pip-audit version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)PIP_AUDIT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "pypi",
|
|
"depNameTemplate": "pip-audit"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "yamllint version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)YAMLLINT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "pypi",
|
|
"depNameTemplate": "yamllint"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "hadolint version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)HADOLINT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "hadolint/hadolint"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "stakater/reloader chart version pinned in the deploy workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
|
"matchStrings": ["\\|stakater/reloader\\|reloader\\|(?<currentValue>[0-9.]+)\\|"],
|
|
"datasourceTemplate": "helm",
|
|
"depNameTemplate": "reloader",
|
|
"registryUrlTemplate": "https://stakater.github.io/stakater-charts"
|
|
}
|
|
],
|
|
"packageRules": [
|
|
{
|
|
"description": "Keep private homelab images unchanged",
|
|
"matchDatasources": ["docker"],
|
|
"matchPackageNames": ["/gcr\\.forust\\.xyz\\/forust\\/.+/"],
|
|
"enabled": false
|
|
},
|
|
{
|
|
"description": "singlesource playwright - use whichever version is found, keep docker+pypi+npm in sync",
|
|
"matchPackageNames": ["playwright", "mcr.microsoft.com/playwright"],
|
|
"groupName": "playwright singlesource",
|
|
"groupSlug": "playwright"
|
|
},
|
|
{
|
|
"description": "playwright must not automerge - version skew breaks the WS handshake (checker.py:1523 vs playwright.yaml:20)",
|
|
"matchPackageNames": ["playwright", "mcr.microsoft.com/playwright"],
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Renovate updates itself in lockstep across the CronJob and the Compose file",
|
|
"matchPackageNames": ["renovate/renovate"],
|
|
"groupName": "renovate self-update",
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Helm chart bumps change PVC fields and admission behaviour, keep them reviewable",
|
|
"matchDatasources": ["helm"],
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Require approval for major upgrades",
|
|
"matchUpdateTypes": ["major"],
|
|
"dependencyDashboardApproval": true,
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Group container patch updates",
|
|
"matchDatasources": ["docker"],
|
|
"matchUpdateTypes": ["patch"],
|
|
"groupName": "container patch updates"
|
|
}
|
|
]
|
|
}
|