[PR #36] [MERGED] chore: Configure Renovate #22

Closed
opened 2026-06-08 09:15:30 +00:00 by ryangr0 · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/webgrip/invoiceninja-application/pull/36
Author: @webgrip-renovate[bot]
Created: 2/9/2026
Status: Merged
Merged: 2/13/2026
Merged by: @Ryangr0

Base: mainHead: renovate/configure


📝 Commits (1)

📊 Changes

1 file changed (+3 additions, -0 deletions)

View changed files

renovate.json (+3 -0)

📄 Description

Welcome to Renovate! This is an onboarding PR to help you understand and configure settings before regular Pull Requests begin.

🚦 Renovate will begin keeping your dependencies up-to-date only once you merge or close this Pull Request.


Detected Package Files

  • docker-compose.yml (docker-compose)
  • ops/docker/application/Dockerfile (dockerfile)
  • ops/docker/mariadb/Dockerfile (dockerfile)
  • ops/docker/mkcert/Dockerfile (dockerfile)
  • ops/docker/nginx/Dockerfile (dockerfile)
  • ops/docker/postgres/Dockerfile (dockerfile)
  • ops/docker/redis/Dockerfile (dockerfile)
  • .github/workflows/on_docs_change.yml (github-actions)
  • .github/workflows/on_release_published.yml (github-actions)
  • .github/workflows/on_source_change.yml (github-actions)
  • ops/helm/invoiceninja-application/values.yaml (helm-values)
  • package.json (npm)

Configuration Summary

Based on the default config's presets, Renovate will:

  • Start dependency updates only once this onboarding PR is merged
  • Enable Renovate Dependency Dashboard creation.
  • Use semantic commit type fix for dependencies and chore for all others if semantic commits are in use.
  • Ignore node_modules, bower_components, vendor and various test/tests (except for nuget) directories.
  • Group known monorepo packages together.
  • Use curated list of recommended non-monorepo package groupings.
  • Show only the Age and Confidence Merge Confidence badges for pull requests.
  • Apply crowd-sourced package replacement rules.
  • Apply crowd-sourced workarounds for known problems with packages.
  • Ensure that every dependency pinned by digest and sourced from GitHub.com contains a link to the commit-to-commit diff
  • Correctly link to the source code for golang.org/x packages
  • Link to pkg.go.dev/... for golang.org/x packages' title
  • Enable Renovate Dependency Dashboard creation.
  • Apply labels dependencies and {{arg1}} to PRs.
  • Enable Renovate configuration migration PRs when needed.
  • Pin Docker digests.
  • Pin github-action digests.
  • Pin dependency versions for development dependencies.
  • Run lock file maintenance (updates) early Monday mornings.
  • Recommended configuration for abandoned packages, treating packages without a release for 1 year as abandoned, while taking into account community-sourced overrides.
  • Wait until the npm package is three days old before raising the update. This a) introduces a short delay to allow for malware researchers and scanners to (possibly) detect any malicious behaviour in packages, and b) prevents the maintainer and/or NPM from unpublishing a package you already upgraded to, breaking builds.

🔡 Do you want to change how Renovate upgrades your dependencies? Add your custom config to renovate.json in this branch. Renovate will update the Pull Request description the next time it runs.


What to Expect

With your current configuration, Renovate will create 4 Pull Requests:

chore(deps): pin docker.io/webgrip/invoiceninja-application docker tag to 81a811f
  • Schedule: ["at any time"]
  • Branch name: renovate/gitops-container-images
  • Merge into: main
  • Upgrade docker.io/webgrip/invoiceninja-application to sha256:81a811ff3f1e23eacb281bcb185980d566ad0054674515ffba06f9f670d09a92
chore(deps): update application container images
  • Schedule: ["at any time"]
  • Branch name: renovate/application-container-images
  • Merge into: main
  • Upgrade mariadb to sha256:7fcb6109db2ba31b22a5709c1eaf9e84f76c9f1b9b9031ef09f24092f7f207cc
  • Upgrade nginx to sha256:1d13701a5f9f3fb01aaa88cef2344d65b6b5bf6b7d9fa4cf0dca557a8d7702ba
  • Upgrade postgres to sha256:bb377b7239d2774ac8cc76f481596ce96c5a6b5e9d141f6d0a0ee371a6e7c0f2
  • Upgrade redis to sha256:02f2cc4882f8bf87c79a220ac958f58c700bdec0dfb9b9ea61b62fb0e8f1bfcf
  • Upgrade vishnunair/docker-mkcert to sha256:bbaff8dac84f4d6fe5ffe36d954e838347864adfb0ae434106ef5b6d188e8729
chore(deps): update application container images (major)
  • Schedule: ["at any time"]
  • Branch name: renovate/major-application-container-images
  • Merge into: main
  • Upgrade mariadb to sha256:e487701b1f7e3f47319fe005b417c72becb67824a58b7bd35c6505f070f66dcd
  • Upgrade postgres to sha256:aa6eb304ddb6dd26df23d05db4e5cb05af8951cda3e0dc57731b771e0ef4ab29
  • Upgrade redis to sha256:fd83658b0e40e2164617d262f13c02ca9ee9e1e6b276fd2fa06617e09bd5c780
chore(deps): lock file maintenance
  • Schedule: ["* 0-3 * * 1"]
  • Branch name: renovate/lock-file-maintenance
  • Merge into: main
  • Regenerate lock files to use latest dependency versions

Warning

Please correct - or verify that you can safely ignore - these dependency lookup failures before you merge this PR.

  • invoiceninja/invoiceninja: Response code 429 (Too Many Requests)
  • nginxinc/nginx-unprivileged: Response code 429 (Too Many Requests)
  • bitnamilegacy/redis: Response code 429 (Too Many Requests)
  • bitnamilegacy/mariadb: Response code 429 (Too Many Requests)

Files affected: ops/docker/application/Dockerfile, ops/helm/invoiceninja-application/values.yaml


Got questions? Check out Renovate's Docs, particularly the Getting Started section.
If you need any further assistance then you can also request help here.


This PR has been generated by Renovate Bot.


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/webgrip/invoiceninja-application/pull/36 **Author:** [@webgrip-renovate[bot]](https://github.com/apps/webgrip-renovate) **Created:** 2/9/2026 **Status:** ✅ Merged **Merged:** 2/13/2026 **Merged by:** [@Ryangr0](https://github.com/Ryangr0) **Base:** `main` ← **Head:** `renovate/configure` --- ### 📝 Commits (1) - [`b2dc472`](https://github.com/webgrip/invoiceninja-application/commit/b2dc47255e02f1f678a1266aa89b5c0d4e6e7516) Add renovate.json ### 📊 Changes **1 file changed** (+3 additions, -0 deletions) <details> <summary>View changed files</summary> ➕ `renovate.json` (+3 -0) </details> ### 📄 Description Welcome to [Renovate](https://redirect.github.com/renovatebot/renovate)! This is an onboarding PR to help you understand and configure settings before regular Pull Requests begin. 🚦 Renovate will begin keeping your dependencies up-to-date only once you merge or close this Pull Request. --- ### Detected Package Files * `docker-compose.yml` (docker-compose) * `ops/docker/application/Dockerfile` (dockerfile) * `ops/docker/mariadb/Dockerfile` (dockerfile) * `ops/docker/mkcert/Dockerfile` (dockerfile) * `ops/docker/nginx/Dockerfile` (dockerfile) * `ops/docker/postgres/Dockerfile` (dockerfile) * `ops/docker/redis/Dockerfile` (dockerfile) * `.github/workflows/on_docs_change.yml` (github-actions) * `.github/workflows/on_release_published.yml` (github-actions) * `.github/workflows/on_source_change.yml` (github-actions) * `ops/helm/invoiceninja-application/values.yaml` (helm-values) * `package.json` (npm) ### Configuration Summary Based on the default config's presets, Renovate will: - Start dependency updates only once this onboarding PR is merged - Enable Renovate Dependency Dashboard creation. - Use semantic commit type `fix` for dependencies and `chore` for all others if semantic commits are in use. - Ignore `node_modules`, `bower_components`, `vendor` and various test/tests (except for nuget) directories. - Group known monorepo packages together. - Use curated list of recommended non-monorepo package groupings. - Show only the Age and Confidence Merge Confidence badges for pull requests. - Apply crowd-sourced package replacement rules. - Apply crowd-sourced workarounds for known problems with packages. - Ensure that every dependency pinned by digest and sourced from GitHub.com contains a link to the commit-to-commit diff - Correctly link to the source code for golang.org/x packages - Link to pkg.go.dev/... for golang.org/x packages' title - Enable Renovate Dependency Dashboard creation. - Apply labels `dependencies` and `{{arg1}}` to PRs. - Enable Renovate configuration migration PRs when needed. - Pin Docker digests. - Pin `github-action` digests. - Pin dependency versions for development dependencies. - Run lock file maintenance (updates) early Monday mornings. - Recommended configuration for abandoned packages, treating packages without a release for 1 year as abandoned, while taking into account community-sourced overrides. - Wait until the npm package is three days old before raising the update. This a) introduces a short delay to allow for malware researchers and scanners to (possibly) detect any malicious behaviour in packages, and b) prevents the maintainer and/or NPM from unpublishing a package you already upgraded to, breaking builds. 🔡 Do you want to change how Renovate upgrades your dependencies? Add your custom config to `renovate.json` in this branch. Renovate will update the Pull Request description the next time it runs. --- ### What to Expect With your current configuration, Renovate will create 4 Pull Requests: <details> <summary>chore(deps): pin docker.io/webgrip/invoiceninja-application docker tag to 81a811f</summary> - Schedule: ["at any time"] - Branch name: `renovate/gitops-container-images` - Merge into: `main` - Upgrade docker.io/webgrip/invoiceninja-application to `sha256:81a811ff3f1e23eacb281bcb185980d566ad0054674515ffba06f9f670d09a92` </details> <details> <summary>chore(deps): update application container images</summary> - Schedule: ["at any time"] - Branch name: `renovate/application-container-images` - Merge into: `main` - Upgrade mariadb to `sha256:7fcb6109db2ba31b22a5709c1eaf9e84f76c9f1b9b9031ef09f24092f7f207cc` - Upgrade nginx to `sha256:1d13701a5f9f3fb01aaa88cef2344d65b6b5bf6b7d9fa4cf0dca557a8d7702ba` - Upgrade postgres to `sha256:bb377b7239d2774ac8cc76f481596ce96c5a6b5e9d141f6d0a0ee371a6e7c0f2` - Upgrade redis to `sha256:02f2cc4882f8bf87c79a220ac958f58c700bdec0dfb9b9ea61b62fb0e8f1bfcf` - Upgrade vishnunair/docker-mkcert to `sha256:bbaff8dac84f4d6fe5ffe36d954e838347864adfb0ae434106ef5b6d188e8729` </details> <details> <summary>chore(deps): update application container images (major)</summary> - Schedule: ["at any time"] - Branch name: `renovate/major-application-container-images` - Merge into: `main` - Upgrade mariadb to `sha256:e487701b1f7e3f47319fe005b417c72becb67824a58b7bd35c6505f070f66dcd` - Upgrade postgres to `sha256:aa6eb304ddb6dd26df23d05db4e5cb05af8951cda3e0dc57731b771e0ef4ab29` - Upgrade redis to `sha256:fd83658b0e40e2164617d262f13c02ca9ee9e1e6b276fd2fa06617e09bd5c780` </details> <details> <summary>chore(deps): lock file maintenance</summary> - Schedule: ["* 0-3 * * 1"] - Branch name: `renovate/lock-file-maintenance` - Merge into: `main` - Regenerate lock files to use latest dependency versions </details> --- > > [!WARNING] > Please correct - or verify that you can safely ignore - these dependency lookup failures before you merge this PR. > > - `invoiceninja/invoiceninja: Response code 429 (Too Many Requests)` > - `nginxinc/nginx-unprivileged: Response code 429 (Too Many Requests)` > - `bitnamilegacy/redis: Response code 429 (Too Many Requests)` > - `bitnamilegacy/mariadb: Response code 429 (Too Many Requests)` > > Files affected: `ops/docker/application/Dockerfile`, `ops/helm/invoiceninja-application/values.yaml` --- ❓ Got questions? Check out Renovate's [Docs](https://docs.renovatebot.com/), particularly the Getting Started section. If you need any further assistance then you can also [request help here](https://redirect.github.com/renovatebot/renovate/discussions). --- This PR has been generated by [Renovate Bot](https://redirect.github.com/renovatebot/renovate). <!--renovate-config-hash:94693a990c975907e7f13da3309b9d56ba02b3983519b41786edf5cf031e457c--> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
ryangr0 2026-06-08 09:15:30 +00:00
Sign in to join this conversation.
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/invoiceninja-application#22
No description provided.