mirror of
https://github.com/Sea-Haven-Industries/engineering-handbook.git
synced 2026-10-07 12:49:04 +00:00
chore(scripts): provision repos with renovate.json and no Dependabot update PRs (#52)
Some checks failed
ci / ci / ci (push) Has been cancelled
Some checks failed
ci / ci / ci (push) Has been cancelled
This commit is contained in:
parent
efec84a07a
commit
0e999fc8a4
1 changed files with 20 additions and 8 deletions
|
|
@ -186,26 +186,37 @@ gh secret set AWS_DEPLOY_ROLE_ARN \
|
|||
echo " Secret set."
|
||||
|
||||
# 4. Enable security features
|
||||
# Dependabot alerts stay on. Dependabot security-update PRs are not enabled:
|
||||
# Renovate opens CVE fix PRs once the repo is Interactive (github-standards.md).
|
||||
echo ""
|
||||
echo "[4/5] Enabling security features..."
|
||||
gh api "repos/${ORG}/${REPO_NAME}/vulnerability-alerts" -X PUT 2>/dev/null || true
|
||||
gh api "repos/${ORG}/${REPO_NAME}" -X PATCH \
|
||||
-f security_and_analysis.dependabot_security_updates.status=enabled \
|
||||
-f security_and_analysis.dependabot_security_updates.status=disabled \
|
||||
-f security_and_analysis.secret_scanning.status=enabled \
|
||||
--silent 2>/dev/null || true
|
||||
echo " Dependabot alerts, security updates, and secret scanning enabled."
|
||||
echo " Dependabot alerts and secret scanning enabled; Dependabot security-update PRs off (Renovate handles them)."
|
||||
|
||||
# 5. Create CI/CD workflow stubs
|
||||
# 5. Create CI/CD workflow stubs and the Renovate config
|
||||
echo ""
|
||||
echo "[5/5] Creating CI/CD workflow files..."
|
||||
echo "[5/5] Creating CI/CD workflow files and renovate.json..."
|
||||
|
||||
REPO_DIR="${HOME}/Documents/repositories/${REPO_NAME}"
|
||||
if [[ ! -d "${REPO_DIR}" ]]; then
|
||||
echo " Repo not cloned locally — skipping workflow file creation."
|
||||
echo " Clone it and re-run, or create .github/workflows/ manually."
|
||||
echo " Repo not cloned locally — skipping workflow and renovate.json creation."
|
||||
echo " Clone it and re-run, or create .github/workflows/ and renovate.json manually."
|
||||
else
|
||||
mkdir -p "${REPO_DIR}/.github/workflows"
|
||||
|
||||
# Renovate, not Dependabot. The org preset chain is inherited from
|
||||
# renovate-config; this file makes it visible in the repo.
|
||||
cat > "${REPO_DIR}/renovate.json" <<'RENOVATEEOF'
|
||||
{
|
||||
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
||||
"extends": ["local>Sea-Haven-Industries/.github"]
|
||||
}
|
||||
RENOVATEEOF
|
||||
|
||||
if [[ "$STACK_TYPE" == "cdk" ]]; then
|
||||
cat > "${REPO_DIR}/.github/workflows/ci.yaml" <<CIEOF
|
||||
name: CI
|
||||
|
|
@ -258,7 +269,7 @@ jobs:
|
|||
deploy-role-arn: \${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
||||
CDEOF
|
||||
fi
|
||||
echo " Created ci.yaml and deploy.yaml pinned to ${WORKFLOW_VERSION}"
|
||||
echo " Created ci.yaml and deploy.yaml pinned to ${WORKFLOW_VERSION}, and renovate.json"
|
||||
fi
|
||||
|
||||
echo ""
|
||||
|
|
@ -266,5 +277,6 @@ echo "=== Provisioning complete ==="
|
|||
echo ""
|
||||
echo "Remaining manual steps:"
|
||||
echo " 1. Create any Secrets Manager secrets needed (${REPO_NAME}/secret-name)"
|
||||
echo " 2. Commit the workflow files on a conventional branch"
|
||||
echo " 2. Commit the workflow files and renovate.json on a conventional branch"
|
||||
echo " 3. Open a PR and verify the ci / ci check passes"
|
||||
echo " 4. Flip the repo from Silent to Interactive in the Mend Developer Portal when it should receive Renovate PRs"
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue