chore(renovate): stop gating patch and minor updates behind a dashboard tick #134

Open
ryangr0 wants to merge 1 commit from chore/renovate-approve-patch-minor into main
Owner

The Dependency Dashboard has 31 items pending approval. Ticking them clears the backlog once; this stops it re-accumulating.

Why there are 31

webgrip/renovate-config@v1.5.3 sets dependencyDashboardApproval: true for major, minor, patch, pin, digest, replacement, rollback — every update type except vulnerability. Nothing in this repo overrides it, so every patch bump waits for a human tick.

That default is correct where a merged bump ships straight to production. It isn't here:

  • build-check builds every changed image on the PR;
  • the release path measures the image against its cve-budgets.yaml entry before it can publish.

So the tick adds a human step without adding a check.

Why 31 pending is worse than no gate

A queue nobody works is indistinguishable from a queue with nothing important in it. The two things in there that genuinely need a person — helm v4.2.4, cosign v3.1.3, and the Node 20→22/24 majors — were invisible among 28 patch bumps.

What changes

patch, minor, pin, digest, bump no longer need a tick. major, rollback and replacement still do — those are decisions, not bumps. The preset's prConcurrentLimit: 5 still caps how many PRs exist at once.

After merging

Renovate opens the ~26 routine bumps by itself, 5 at a time. Worth knowing before merging them: on_source_change uses concurrency group push-${ref}, so any push to main cancels an in-flight release wave — merge these when no wave is running, not back to back.

Still needing you afterwards, as real work rather than ticks:

item why it's not a bump
helm/helm v3 → v4.2.4 major; helm-deploy image + every chart consumer
sigstore/cosign v2 → v3.1.3 major; signing + attestation path, OpenBao JWT role
Node 20 → 22 / 24 major; two competing target versions to choose between
lycheeverse/lychee rollback to v0.15.1 a rollback Renovate proposes — deliberately still gated
The Dependency Dashboard has **31 items pending approval**. Ticking them clears the backlog once; this stops it re-accumulating. ## Why there are 31 `webgrip/renovate-config@v1.5.3` sets `dependencyDashboardApproval: true` for `major, minor, patch, pin, digest, replacement, rollback` — every update type except `vulnerability`. Nothing in this repo overrides it, so every patch bump waits for a human tick. That default is correct where a merged bump ships straight to production. It isn't here: - `build-check` builds every changed image on the PR; - the release path measures the image against its `cve-budgets.yaml` entry before it can publish. So the tick adds a human step without adding a check. ## Why 31 pending is worse than no gate A queue nobody works is indistinguishable from a queue with nothing important in it. The two things in there that genuinely need a person — `helm v4.2.4`, `cosign v3.1.3`, and the Node 20→22/24 majors — were invisible among 28 patch bumps. ## What changes `patch`, `minor`, `pin`, `digest`, `bump` no longer need a tick. **`major`, `rollback` and `replacement` still do** — those are decisions, not bumps. The preset's `prConcurrentLimit: 5` still caps how many PRs exist at once. ## After merging Renovate opens the ~26 routine bumps by itself, 5 at a time. Worth knowing before merging them: `on_source_change` uses concurrency group `push-${ref}`, so any push to main cancels an in-flight release wave — merge these when no wave is running, not back to back. Still needing you afterwards, as real work rather than ticks: | item | why it's not a bump | |---|---| | `helm/helm` v3 → v4.2.4 | major; helm-deploy image + every chart consumer | | `sigstore/cosign` v2 → v3.1.3 | major; signing + attestation path, OpenBao JWT role | | Node 20 → 22 / 24 | major; two competing target versions to choose between | | `lycheeverse/lychee` rollback to v0.15.1 | a rollback Renovate proposes — deliberately still gated |
The org preset puts dependencyDashboardApproval on every update type except
vulnerability fixes. That is the right default for a repo where a bump ships
straight to production; it is the wrong one here, where build-check builds
every changed image on the PR and the release path measures the image against
its cve-budgets.yaml entry before it can publish.

The result was 31 pending ticks, which is worse than having no gate at all: a
queue nobody works is indistinguishable from a queue with nothing important in
it, and the two genuine migrations sitting in it (helm v4, cosign v3, Node
22/24) were invisible among 28 patch bumps.

Majors, rollbacks and replacements keep the gate — those are decisions. The
preset's prConcurrentLimit of 5 still caps how many PRs exist at once.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This pull request can be merged automatically.
This branch is out-of-date with the base branch
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin chore/renovate-approve-patch-minor:chore/renovate-approve-patch-minor
git switch chore/renovate-approve-patch-minor

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff chore/renovate-approve-patch-minor
git switch chore/renovate-approve-patch-minor
git rebase main
git switch main
git merge --ff-only chore/renovate-approve-patch-minor
git switch chore/renovate-approve-patch-minor
git rebase main
git switch main
git merge --no-ff chore/renovate-approve-patch-minor
git switch main
git merge --squash chore/renovate-approve-patch-minor
git switch main
git merge --ff-only chore/renovate-approve-patch-minor
git switch main
git merge chore/renovate-approve-patch-minor
git push origin main
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/infrastructure!134
No description provided.