Repository navigation
Conversation
The Renovate App runs in Silent mode for the org: it scans this repo daily but only acts on repositories that carry their own config and never opens an onboarding PR, so it has never touched this repo. Add the config; see the header comment for the policy and what is specific to this repository.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The Renovate App is installed for every overcast-sh repository and runs in Silent mode: it scans each repo daily but only acts on one that carries its own config, and it never opens an onboarding PR. The Mend portal shows this repo as "onboarded" with a job run yesterday, yet Renovate has never opened anything here because there was nothing to activate it. This file is the activation, the same as overcast-sh/website#53.
What the config does
Adapted from the website config:
npmandgithub-actions.storybookand every@storybook/*package move together across every update type, as doreact,react-domand their type packages, so a bump never lands half a lockstep set.rangeStrategy: bump, because every dependency is a caret range and Renovate's default would otherwise never open a non-major PR.minimumReleaseAge, OSV vulnerability alerts that bypass it, a weekly Monday schedule, monthlylockFileMaintenance, andrebaseWhen: behind-base-branch.semanticCommitsdisabled to match this repo's plain imperative commit subjects.One thing specific to this repo
CI's "Generated assets in sync" job regenerates every visual asset and fails on any diff. A bump of
@resvg/resvg-js,opentype.jsorpng-to-icocan legitimately change the generated bytes, and then the Renovate PR fails that job by design. The hosted App cannot runpostUpgradeTasks, so the reviewer regenerates on the branch, checks the pixel diff, and commits. The config header spells this out so the first such failure is not read as a broken update.What to expect after merge
A Dependency Dashboard issue, then a PR converting the workflow's tag-pinned actions to digest pins (the
helpers:pinGitHubActionDigestspreset, per org policy), then grouped update PRs on Mondays.Validation
renovate-config-validatorcould not be run from this session. The file was parsed as JSON5 and each option reviewed against the Renovate docs and the two working configs in the org. A config error would surface in the dashboard issue rather than fail silently.