Skip to content

Activate Renovate with a config adapted from website - #3

Open
Neaox wants to merge 1 commit into
mainfrom
deps/renovate-config
Open

Neaox wants to merge 1 commit into
mainfrom
deps/renovate-config

Conversation

@Neaox

@Neaox Neaox commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

Why

The Renovate App is installed for every overcast-sh repository and runs in Silent mode: it scans each repo daily but only acts on one that carries its own config, and it never opens an onboarding PR. The Mend portal shows this repo as "onboarded" with a job run yesterday, yet Renovate has never opened anything here because there was nothing to activate it. This file is the activation, the same as overcast-sh/website#53.

What the config does

Adapted from the website config:

  • Managers limited to npm and github-actions.
  • Majors arrive one per PR and are never grouped. Non-major npm updates land as one group, non-major and digest action updates as another.
  • storybook and every @storybook/* package move together across every update type, as do react, react-dom and their type packages, so a bump never lands half a lockstep set.
  • rangeStrategy: bump, because every dependency is a caret range and Renovate's default would otherwise never open a non-major PR.
  • Seven-day minimumReleaseAge, OSV vulnerability alerts that bypass it, a weekly Monday schedule, monthly lockFileMaintenance, and rebaseWhen: behind-base-branch.
  • No automerge. The main-branch ruleset requires no status check, so nothing would gate one.
  • semanticCommits disabled to match this repo's plain imperative commit subjects.

One thing specific to this repo

CI's "Generated assets in sync" job regenerates every visual asset and fails on any diff. A bump of @resvg/resvg-js, opentype.js or png-to-ico can legitimately change the generated bytes, and then the Renovate PR fails that job by design. The hosted App cannot run postUpgradeTasks, so the reviewer regenerates on the branch, checks the pixel diff, and commits. The config header spells this out so the first such failure is not read as a broken update.

What to expect after merge

A Dependency Dashboard issue, then a PR converting the workflow's tag-pinned actions to digest pins (the helpers:pinGitHubActionDigests preset, per org policy), then grouped update PRs on Mondays.

Validation

renovate-config-validator could not be run from this session. The file was parsed as JSON5 and each option reviewed against the Renovate docs and the two working configs in the org. A config error would surface in the dashboard issue rather than fail silently.

The Renovate App runs in Silent mode for the org: it scans this repo daily but
only acts on repositories that carry their own config and never opens an
onboarding PR, so it has never touched this repo. Add the config; see the
header comment for the policy and what is specific to this repository.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant