chore: Configure Renovate - autoclosed #17

Closed
renovate wants to merge 1 commit from renovate/configure into master
Member

Welcome to Renovate! This is an onboarding PR to help you understand and configure settings before regular Pull Requests begin.

🚦 Renovate will begin keeping your dependencies up-to-date only once you merge or close this Pull Request.

📚 See our Reading List for relevant documentation you may be interested in reading.

🔡 Do you want to change how Renovate upgrades your dependencies? Add your custom config to renovate.json in this branch. Renovate will update the Pull Request description the next time it runs.


Detected Package Files

  • docker-compose.yml (docker-compose)
  • ops/docker/grafana/Dockerfile (dockerfile)
  • ops/docker/mariadb/Dockerfile (dockerfile)
  • ops/docker/otel-collector/Dockerfile (dockerfile)
  • ops/docker/tempo/Dockerfile (dockerfile)
  • .forgejo/workflows/on_docs_change.yml (github-actions)
  • .github/workflows/deploy.yml (github-actions)
  • .github/workflows/docker_build_and_push.yml (github-actions)
  • renovate.json (renovate-config)

Configuration Summary

Based on the default config's presets, Renovate will:

  • Start dependency updates only once this onboarding PR is merged
  • Forgejo-platform overrides. Two things the platform gets wrong on its own. (1) Forgejo Actions don't populate the commit-status API that Renovate's prCreation:not-pending reads (GET /commits/{sha}/status is empty even on green CI), so not-pending never resolves and PRs hang the full prNotPendingHours. Force immediate PR creation on the Forgejo path. force: because consumers extend :default (not-pending) at the repo level, which only an admin-level force overrides. (2) The github-actions manager assigns datasource github-tags unconditionally, so a uses: pointing at a Forgejo-native repo is resolved against api.github.com. Where a github.com twin exists but carries no tags, that returns an empty list rather than an error — the pin freezes silently. The customManager below reads webgrip/* reusable-workflow pins from Forgejo instead.
  • Enable Renovate Dependency Dashboard creation.
  • Use semantic commit type fix for dependencies and chore for all others if semantic commits are in use.
  • Ignore node_modules, bower_components, vendor and various test/tests (except for nuget) directories.
  • Group known monorepo packages together.
  • Use curated list of recommended non-monorepo package groupings.
  • Show only the Age and Confidence Merge Confidence badges for pull requests.
  • Apply crowd-sourced package replacement rules.
  • Apply crowd-sourced workarounds for known problems with packages.
  • Ensure that every dependency pinned by digest and sourced from Forgejo contains a link to the commit-to-commit diff
  • Ensure that every dependency pinned by digest and sourced from Gitea contains a link to the commit-to-commit diff
  • Ensure that every dependency pinned by digest and sourced from GitHub.com and Github enterprise contains a link to the commit-to-commit diff
  • Ensure that every dependency pinned by digest and sourced from GitLab.com contains a link to the commit-to-commit diff
  • Correctly link to the source code for golang.org/x packages
  • Link to pkg.go.dev/... for golang.org/x packages' title
  • Provide a link to octochangelog's improved breakdown for Renovate's changelogs
  • Enable Renovate Dependency Dashboard creation.
  • Use semantic prefixes for commit messages and PR titles.
  • Separate each major version of dependencies into individual branches/PRs.
  • Raise PR when vulnerability alerts are detected.
  • Evaluate schedules according to timezone Europe/Amsterdam.
  • Recommended configuration for abandoned packages, treating packages without a release for 1 year as abandoned, while taking into account community-sourced overrides.
  • Show all Merge Confidence badges for pull requests.
  • Webgrip org default Renovate preset — strict, conservative defaults for all repositories. Graduated release soak times, per-type semantic commits and labels, OSV vulnerability alerts, and Merge Confidence badges included. Schedule is 'at any time' since 2026-09-18: with dashboard approval required for every update type, nothing opens unattended anyway, so a window only delayed work a human had already asked for — and Renovate does not persist an approval it cannot act on, so a tick made outside the window could be silently discarded (see rule 12). It also fought the move to hourly runs, which was made to cut exactly this kind of latency. A repo that wants quiet hours can set its own schedule.

What to Expect

With your current configuration, Renovate will create 12 Pull Requests:

ci(actions): Pin dependencies
  • Schedule: ["at any time"]
  • Branch name: renovate/pin-dependencies
  • Merge into: master
  • Pin actions/checkout to 11d5960a326750d5838078e36cf38b85af677262
  • Pin azure/setup-helm to 1a275c3b69536ee54be43f2070a358922e12c8d4
  • Pin azure/setup-kubectl to 776406bce94f63e41d621b960d78ee25c8b76ede
  • Upgrade grafana/grafana-image-renderer to sha256:c13f98282c7f82a8bb0d75048d483045159d7ce04d1d02f5e06b21b26b4e5a0b
  • Upgrade mariadb to sha256:25880dbf51656b317af80e84c8bd5c3184ac6dab48ac3e7df3937bff3d7e0e58
fix(deps): update grafana/grafana-image-renderer docker tag ( 3.11.0 ➔ 3.11.6 )
  • Schedule: ["at any time"]
  • Branch name: renovate/grafana-grafana-image-renderer-3.11.x
  • Merge into: master
  • Upgrade grafana/grafana-image-renderer to sha256:c7af27f500676c96f8b957da30b2aae96b9e892366e2999ddaeff58a710b5a61
fix(deps): update mariadb docker tag ( 11.4.2 ➔ 11.4.13 )
  • Schedule: ["at any time"]
  • Branch name: renovate/mariadb-11.4.x
  • Merge into: master
  • Upgrade mariadb to sha256:6b75923125bdf1e05ebf2414d5b68558f78c7363e5b1bb0b5a7fc0a1836563ad
feat(deps): update grafana/grafana-image-renderer docker tag ( 3.11.0 ➔ 3.12.9 )
  • Schedule: ["at any time"]
  • Branch name: renovate/grafana-grafana-image-renderer-3.x
  • Merge into: master
  • Upgrade grafana/grafana-image-renderer to sha256:6d8650aad54e3efcbe9992ca1bc06e1046c7c15567019d4d289273f60ef59656
feat(deps): update mariadb docker tag ( 11.4.2 ➔ 11.8.9 )
  • Schedule: ["at any time"]
  • Branch name: renovate/mariadb-11.x
  • Merge into: master
  • Upgrade mariadb to sha256:4d6c45144a18908d1244975e5c275fa56e688fbc77f889f27e68e1c5b8cb64d5
ci(actions): Update actions/checkout action ( v4.4.0 ➔ v5.1.0 )
  • Schedule: ["at any time"]
  • Branch name: renovate/actions-checkout-5.x
  • Merge into: master
  • Upgrade actions/checkout to fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09
ci(actions): Update actions/checkout action ( v4.4.0 ➔ v6.1.0 )
  • Schedule: ["at any time"]
  • Branch name: renovate/actions-checkout-6.x
  • Merge into: master
  • Upgrade actions/checkout to d23441a48e516b6c34aea4fa41551a30e30af803
ci(actions): Update actions/checkout action ( v4.4.0 ➔ v7.0.1 )
  • Schedule: ["at any time"]
  • Branch name: renovate/actions-checkout-7.x
  • Merge into: master
  • Upgrade actions/checkout to 3d3c42e5aac5ba805825da76410c181273ba90b1
ci(actions): Update azure/setup-helm action ( v4.3.1 ➔ v5.0.1 )
  • Schedule: ["at any time"]
  • Branch name: renovate/azure-setup-helm-5.x
  • Merge into: master
  • Upgrade azure/setup-helm to 9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310
ci(actions): Update azure/setup-kubectl action ( v4.0.1 ➔ v5.1.0 )
  • Schedule: ["at any time"]
  • Branch name: renovate/azure-setup-kubectl-5.x
  • Merge into: master
  • Upgrade azure/setup-kubectl to 829323503d1be3d00ca8346e5391ca0b07a9ab0d
feat(deps): update grafana/grafana-image-renderer docker tag ( 3.11.0 ➔ v4.1.5 )
  • Schedule: ["at any time"]
  • Branch name: renovate/grafana-grafana-image-renderer-4.x
  • Merge into: master
  • Upgrade grafana/grafana-image-renderer to sha256:e75e9ca76cbb5450d99f4002087a820d0684bef739c7d2f19ebd162e770bcd23
feat(deps): update grafana/grafana-image-renderer docker tag ( 3.11.0 ➔ v5.12.4 )
  • Schedule: ["at any time"]
  • Branch name: renovate/grafana-grafana-image-renderer-5.x
  • Merge into: master
  • Upgrade grafana/grafana-image-renderer to sha256:4c5574b3261ca7566fbca11d3fb3615bd8e753c69cb4fe9108f3ec8d1d3841d6

⚠️ Warning

Please correct - or verify that you can safely ignore - these dependency lookup failures before you merge this PR.

  • Failed to look up docker package grafana/loki: no-result
  • Failed to look up docker package grafana/grafana: no-result
  • Failed to look up docker package otel/opentelemetry-collector-contrib: no-result

Files affected: docker-compose.yml, ops/docker/grafana/Dockerfile, ops/docker/otel-collector/Dockerfile


❓ Got questions? Check out Renovate's Docs, particularly the Getting Started section.
If you need any further assistance then you can also request help here.


This PR has been generated by Mend Renovate.

Welcome to [Renovate](https://github.com/renovatebot/renovate)! This is an onboarding PR to help you understand and configure settings before regular Pull Requests begin. 🚦 Renovate will begin keeping your dependencies up-to-date only once you merge or close this Pull Request. 📚 See our [Reading List](https://docs.renovatebot.com/reading-list/) for relevant documentation you may be interested in reading. 🔡 Do you want to change how Renovate upgrades your dependencies? Add your custom config to `renovate.json` in this branch. Renovate will update the Pull Request description the next time it runs. --- ### Detected Package Files * `docker-compose.yml` (docker-compose) * `ops/docker/grafana/Dockerfile` (dockerfile) * `ops/docker/mariadb/Dockerfile` (dockerfile) * `ops/docker/otel-collector/Dockerfile` (dockerfile) * `ops/docker/tempo/Dockerfile` (dockerfile) * `.forgejo/workflows/on_docs_change.yml` (github-actions) * `.github/workflows/deploy.yml` (github-actions) * `.github/workflows/docker_build_and_push.yml` (github-actions) * `renovate.json` (renovate-config) ### Configuration Summary Based on the default config's presets, Renovate will: - Start dependency updates only once this onboarding PR is merged - Forgejo-platform overrides. Two things the platform gets wrong on its own. (1) Forgejo Actions don't populate the commit-status API that Renovate's prCreation:not-pending reads (GET /commits/{sha}/status is empty even on green CI), so not-pending never resolves and PRs hang the full prNotPendingHours. Force immediate PR creation on the Forgejo path. force: because consumers extend :default (not-pending) at the repo level, which only an admin-level force overrides. (2) The github-actions manager assigns datasource github-tags unconditionally, so a `uses:` pointing at a Forgejo-native repo is resolved against api.github.com. Where a github.com twin exists but carries no tags, that returns an empty list rather than an error — the pin freezes silently. The customManager below reads webgrip/* reusable-workflow pins from Forgejo instead. - Enable Renovate Dependency Dashboard creation. - Use semantic commit type `fix` for dependencies and `chore` for all others if semantic commits are in use. - Ignore `node_modules`, `bower_components`, `vendor` and various test/tests (except for nuget) directories. - Group known monorepo packages together. - Use curated list of recommended non-monorepo package groupings. - Show only the Age and Confidence Merge Confidence badges for pull requests. - Apply crowd-sourced package replacement rules. - Apply crowd-sourced workarounds for known problems with packages. - Ensure that every dependency pinned by digest and sourced from Forgejo contains a link to the commit-to-commit diff - Ensure that every dependency pinned by digest and sourced from Gitea contains a link to the commit-to-commit diff - Ensure that every dependency pinned by digest and sourced from GitHub.com and Github enterprise contains a link to the commit-to-commit diff - Ensure that every dependency pinned by digest and sourced from GitLab.com contains a link to the commit-to-commit diff - Correctly link to the source code for golang.org/x packages - Link to pkg.go.dev/... for golang.org/x packages' title - Provide a link to octochangelog's improved breakdown for Renovate's changelogs - Enable Renovate Dependency Dashboard creation. - Use semantic prefixes for commit messages and PR titles. - Separate each `major` version of dependencies into individual branches/PRs. - Raise PR when vulnerability alerts are detected. - Evaluate schedules according to timezone `Europe/Amsterdam`. - Recommended configuration for abandoned packages, treating packages without a release for 1 year as abandoned, while taking into account community-sourced overrides. - Show all Merge Confidence badges for pull requests. - Webgrip org default Renovate preset — strict, conservative defaults for all repositories. Graduated release soak times, per-type semantic commits and labels, OSV vulnerability alerts, and Merge Confidence badges included. Schedule is 'at any time' since 2026-09-18: with dashboard approval required for every update type, nothing opens unattended anyway, so a window only delayed work a human had already asked for — and Renovate does not persist an approval it cannot act on, so a tick made outside the window could be silently discarded (see rule 12). It also fought the move to hourly runs, which was made to cut exactly this kind of latency. A repo that wants quiet hours can set its own schedule. --- ### What to Expect With your current configuration, Renovate will create 12 Pull Requests: <details> <summary>ci(actions): Pin dependencies</summary> - Schedule: ["at any time"] - Branch name: `renovate/pin-dependencies` - Merge into: `master` - Pin [actions/checkout](https://github.com/actions/checkout) to `11d5960a326750d5838078e36cf38b85af677262` - Pin [azure/setup-helm](https://github.com/azure/setup-helm) to `1a275c3b69536ee54be43f2070a358922e12c8d4` - Pin [azure/setup-kubectl](https://github.com/azure/setup-kubectl) to `776406bce94f63e41d621b960d78ee25c8b76ede` - Upgrade grafana/grafana-image-renderer to `sha256:c13f98282c7f82a8bb0d75048d483045159d7ce04d1d02f5e06b21b26b4e5a0b` - Upgrade mariadb to `sha256:25880dbf51656b317af80e84c8bd5c3184ac6dab48ac3e7df3937bff3d7e0e58` </details> <details> <summary>fix(deps): update grafana/grafana-image-renderer docker tag ( 3.11.0 ➔ 3.11.6 )</summary> - Schedule: ["at any time"] - Branch name: `renovate/grafana-grafana-image-renderer-3.11.x` - Merge into: `master` - Upgrade grafana/grafana-image-renderer to `sha256:c7af27f500676c96f8b957da30b2aae96b9e892366e2999ddaeff58a710b5a61` </details> <details> <summary>fix(deps): update mariadb docker tag ( 11.4.2 ➔ 11.4.13 )</summary> - Schedule: ["at any time"] - Branch name: `renovate/mariadb-11.4.x` - Merge into: `master` - Upgrade mariadb to `sha256:6b75923125bdf1e05ebf2414d5b68558f78c7363e5b1bb0b5a7fc0a1836563ad` </details> <details> <summary>feat(deps): update grafana/grafana-image-renderer docker tag ( 3.11.0 ➔ 3.12.9 )</summary> - Schedule: ["at any time"] - Branch name: `renovate/grafana-grafana-image-renderer-3.x` - Merge into: `master` - Upgrade grafana/grafana-image-renderer to `sha256:6d8650aad54e3efcbe9992ca1bc06e1046c7c15567019d4d289273f60ef59656` </details> <details> <summary>feat(deps): update mariadb docker tag ( 11.4.2 ➔ 11.8.9 )</summary> - Schedule: ["at any time"] - Branch name: `renovate/mariadb-11.x` - Merge into: `master` - Upgrade mariadb to `sha256:4d6c45144a18908d1244975e5c275fa56e688fbc77f889f27e68e1c5b8cb64d5` </details> <details> <summary>ci(actions): Update actions/checkout action ( v4.4.0 ➔ v5.1.0 )</summary> - Schedule: ["at any time"] - Branch name: `renovate/actions-checkout-5.x` - Merge into: `master` - Upgrade [actions/checkout](https://github.com/actions/checkout) to `fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09` </details> <details> <summary>ci(actions): Update actions/checkout action ( v4.4.0 ➔ v6.1.0 )</summary> - Schedule: ["at any time"] - Branch name: `renovate/actions-checkout-6.x` - Merge into: `master` - Upgrade [actions/checkout](https://github.com/actions/checkout) to `d23441a48e516b6c34aea4fa41551a30e30af803` </details> <details> <summary>ci(actions): Update actions/checkout action ( v4.4.0 ➔ v7.0.1 )</summary> - Schedule: ["at any time"] - Branch name: `renovate/actions-checkout-7.x` - Merge into: `master` - Upgrade [actions/checkout](https://github.com/actions/checkout) to `3d3c42e5aac5ba805825da76410c181273ba90b1` </details> <details> <summary>ci(actions): Update azure/setup-helm action ( v4.3.1 ➔ v5.0.1 )</summary> - Schedule: ["at any time"] - Branch name: `renovate/azure-setup-helm-5.x` - Merge into: `master` - Upgrade [azure/setup-helm](https://github.com/azure/setup-helm) to `9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310` </details> <details> <summary>ci(actions): Update azure/setup-kubectl action ( v4.0.1 ➔ v5.1.0 )</summary> - Schedule: ["at any time"] - Branch name: `renovate/azure-setup-kubectl-5.x` - Merge into: `master` - Upgrade [azure/setup-kubectl](https://github.com/azure/setup-kubectl) to `829323503d1be3d00ca8346e5391ca0b07a9ab0d` </details> <details> <summary>feat(deps): update grafana/grafana-image-renderer docker tag ( 3.11.0 ➔ v4.1.5 )</summary> - Schedule: ["at any time"] - Branch name: `renovate/grafana-grafana-image-renderer-4.x` - Merge into: `master` - Upgrade grafana/grafana-image-renderer to `sha256:e75e9ca76cbb5450d99f4002087a820d0684bef739c7d2f19ebd162e770bcd23` </details> <details> <summary>feat(deps): update grafana/grafana-image-renderer docker tag ( 3.11.0 ➔ v5.12.4 )</summary> - Schedule: ["at any time"] - Branch name: `renovate/grafana-grafana-image-renderer-5.x` - Merge into: `master` - Upgrade grafana/grafana-image-renderer to `sha256:4c5574b3261ca7566fbca11d3fb3615bd8e753c69cb4fe9108f3ec8d1d3841d6` </details> --- > > ⚠️ **Warning** > > Please correct - or verify that you can safely ignore - these dependency lookup failures before you merge this PR. > > - `Failed to look up docker package grafana/loki: no-result` > - `Failed to look up docker package grafana/grafana: no-result` > - `Failed to look up docker package otel/opentelemetry-collector-contrib: no-result` > > Files affected: `docker-compose.yml`, `ops/docker/grafana/Dockerfile`, `ops/docker/otel-collector/Dockerfile` --- ❓ Got questions? Check out Renovate's [Docs](https://docs.renovatebot.com/), particularly the Getting Started section. If you need any further assistance then you can also [request help here](https://github.com/renovatebot/renovate/discussions). --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-config-hash:b2f1103e37fc2c0c9669edfd6f4c5476b2c8f24642334cef536b7118f8487c58-->
chore(deps): add renovate.json
Some checks failed
deploy.yml / chore(deps): add renovate.json (push) Failing after 0s
docker_build_and_push.yml / chore(deps): add renovate.json (push) Failing after 0s
deploy.yml / chore(deps): add renovate.json (pull_request) Failing after 0s
docker_build_and_push.yml / chore(deps): add renovate.json (pull_request) Failing after 0s
d6752bafd4
renovate changed title from chore: Configure Renovate to chore: Configure Renovate - autoclosed 2026-09-22 06:54:09 +00:00
renovate closed this pull request 2026-09-22 06:54:09 +00:00
Some checks failed
deploy.yml / chore(deps): add renovate.json (push) Failing after 0s
docker_build_and_push.yml / chore(deps): add renovate.json (push) Failing after 0s
deploy.yml / chore(deps): add renovate.json (pull_request) Failing after 0s
docker_build_and_push.yml / chore(deps): add renovate.json (pull_request) Failing after 0s

Pull request closed

Sign in to join this conversation.
No reviewers
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/monitoring-platform!17
No description provided.