chore(renovate): stop gating patch and minor updates behind a dashboard tick #134
Open
ryangr0
wants to merge 1 commit from
chore/renovate-approve-patch-minor into main
pull from: chore/renovate-approve-patch-minor
merge into: webgrip:main
webgrip:main
webgrip:fix/composite-manifest-install
webgrip:feat/agent-runner-dhi-alpine
webgrip:feat/techdocs-builder-dhi
webgrip:feat/semrel-family-dhi-alpine
webgrip:feat/semantic-release-monorepo-dhi-base
webgrip:feat/semantic-release-dhi-base
webgrip:feat/node-ci-runner-dhi-base
webgrip:feat/helm-deploy-dhi-base
webgrip:feat/act-runner-dhi-base
webgrip:fix/promote-dash-candidate
webgrip:perf/consolidate-release-plumbing
webgrip:fix/helm-deploy-tool-bumps
webgrip:fix/candidate-keyed-by-version
webgrip:feat/promote-by-digest
webgrip:feat/cve-budgets-measured
webgrip:diag/measure-cve-budgets
webgrip:fix/techdocs-builder-zensical-conflict
webgrip:fix/semantic-release-rust-signed-reentry
webgrip:fix/node-ci-runner-signed-reentry
webgrip:docs/hardening-wave3-plan
webgrip:fix/techdocs-runner-pin-parent
webgrip:fix/mkdocs-runner-pin-parent
webgrip:fix/tauri-ci-runner-pin-parent
webgrip:fix/ci-runner-signed-cve-gate
webgrip:fix/helm-deploy-verify-downloads
webgrip:fix/techdocs-builder-annotate-stages
webgrip:fix/rust-ci-runner-pin-build-stage
webgrip:fix/rust-releaser-pin-toolchain
webgrip:fix/semantic-release-rust-pin-base
webgrip:fix/semantic-release-monorepo-pin-base
webgrip:fix/semantic-release-pin-base
webgrip:fix/playwright-runner-pin-base
webgrip:fix/act-runner-pin-act
webgrip:fix/node-ci-runner-pin-base
webgrip:fix/bump-workflows-pin-codeberg-bash
webgrip:fix/renovate-digest-aware-args
webgrip:docs/upstream-vex-in-harbor
webgrip:fix/harbor-sbom-honest-report
webgrip:fix/vex-aliases-and-unmatched-guard
webgrip:fix/gate-stderr-not-a-tty
webgrip:perf/drop-installer-actions
webgrip:fix/release-matrix-multiline-output
webgrip:fix/cve-gate-header-accuracy
webgrip:feat/release-manual-trigger
webgrip:fix/ci-runner-claude-code-and-renovate-annotation
webgrip:docs/adr-buildkitd-and-gate-as-step
webgrip:perf/release-verify-uses-buildkitd
webgrip:perf/cve-gate-as-a-step
webgrip:perf/ci-runner-bake-gate
webgrip:fix/cve-gate-volume-ownership
webgrip:fix/ci-runner-verify-helm-yq
webgrip:fix/cve-gate-scan-space
webgrip:chore/oci-labels-batch1
webgrip:perf/build-check-cli
webgrip:chore/forgejo-git-throughput-probe
webgrip:perf/ci-runner-bake-cosign-syft
webgrip:fix/cve-gate-seccomp-clone
webgrip:fix/cve-gate-pin-existing-version
webgrip:fix/cve-gate-readonly-inputs
webgrip:fix/cve-gate-moby-floor
webgrip:feat/cve-gate-static
webgrip:fix/cve-gate-vex-and-budget
webgrip:fix/cve-gate-staging-root
webgrip:ci/build-check-on-branches
webgrip:fix/cve-gate-dhi-registry
webgrip:feat/cve-gate
webgrip:feat/harden-supply-chain
webgrip:fix/semrel-toolchain-one-source
webgrip:fix/semrel-fork-direct-binary
webgrip:renovate/actions-attest-build-provenance-3.x
webgrip:renovate/sigstore-cosign-installer-4.x
webgrip:renovate/github-codeql-action-4.x
webgrip:renovate/docker-login-action-4.x
webgrip:renovate/actions-create-github-app-token-3.x
webgrip:renovate/actions-attest-build-provenance-4.x
webgrip:copilot/fix-docker-build-and-push
webgrip:copilot/fix-1
No reviewers
No labels
pull-request
released
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set.
Reference
webgrip/infrastructure!134
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "chore/renovate-approve-patch-minor"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The Dependency Dashboard has 31 items pending approval. Ticking them clears the backlog once; this stops it re-accumulating.
Why there are 31
webgrip/renovate-config@v1.5.3setsdependencyDashboardApproval: trueformajor, minor, patch, pin, digest, replacement, rollback— every update type exceptvulnerability. Nothing in this repo overrides it, so every patch bump waits for a human tick.That default is correct where a merged bump ships straight to production. It isn't here:
build-checkbuilds every changed image on the PR;cve-budgets.yamlentry before it can publish.So the tick adds a human step without adding a check.
Why 31 pending is worse than no gate
A queue nobody works is indistinguishable from a queue with nothing important in it. The two things in there that genuinely need a person —
helm v4.2.4,cosign v3.1.3, and the Node 20→22/24 majors — were invisible among 28 patch bumps.What changes
patch,minor,pin,digest,bumpno longer need a tick.major,rollbackandreplacementstill do — those are decisions, not bumps. The preset'sprConcurrentLimit: 5still caps how many PRs exist at once.After merging
Renovate opens the ~26 routine bumps by itself, 5 at a time. Worth knowing before merging them:
on_source_changeuses concurrency grouppush-${ref}, so any push to main cancels an in-flight release wave — merge these when no wave is running, not back to back.Still needing you afterwards, as real work rather than ticks:
helm/helmv3 → v4.2.4sigstore/cosignv2 → v3.1.3lycheeverse/lycheerollback to v0.15.1View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.