chore(scripts): provision repos with renovate.json and no Dependabot update PRs

This commit is contained in:
Adam Moussa 2026-10-05 14:13:11 -04:00
parent efec84a07a
commit a6d0befe46
No known key found for this signature in database

View file

@ -186,26 +186,37 @@ gh secret set AWS_DEPLOY_ROLE_ARN \
echo " Secret set."
# 4. Enable security features
# Dependabot alerts stay on. Dependabot security-update PRs are not enabled:
# Renovate opens CVE fix PRs once the repo is Interactive (github-standards.md).
echo ""
echo "[4/5] Enabling security features..."
gh api "repos/${ORG}/${REPO_NAME}/vulnerability-alerts" -X PUT 2>/dev/null || true
gh api "repos/${ORG}/${REPO_NAME}" -X PATCH \
-f security_and_analysis.dependabot_security_updates.status=enabled \
-f security_and_analysis.dependabot_security_updates.status=disabled \
-f security_and_analysis.secret_scanning.status=enabled \
--silent 2>/dev/null || true
echo " Dependabot alerts, security updates, and secret scanning enabled."
echo " Dependabot alerts and secret scanning enabled; Dependabot security-update PRs off (Renovate handles them)."
# 5. Create CI/CD workflow stubs
# 5. Create CI/CD workflow stubs and the Renovate config
echo ""
echo "[5/5] Creating CI/CD workflow files..."
echo "[5/5] Creating CI/CD workflow files and renovate.json..."
REPO_DIR="${HOME}/Documents/repositories/${REPO_NAME}"
if [[ ! -d "${REPO_DIR}" ]]; then
echo " Repo not cloned locally — skipping workflow file creation."
echo " Clone it and re-run, or create .github/workflows/ manually."
echo " Repo not cloned locally — skipping workflow and renovate.json creation."
echo " Clone it and re-run, or create .github/workflows/ and renovate.json manually."
else
mkdir -p "${REPO_DIR}/.github/workflows"
# Renovate, not Dependabot. The org preset chain is inherited from
# renovate-config; this file makes it visible in the repo.
cat > "${REPO_DIR}/renovate.json" <<'RENOVATEEOF'
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": ["local>Sea-Haven-Industries/.github"]
}
RENOVATEEOF
if [[ "$STACK_TYPE" == "cdk" ]]; then
cat > "${REPO_DIR}/.github/workflows/ci.yaml" <<CIEOF
name: CI
@ -258,7 +269,7 @@ jobs:
deploy-role-arn: \${{ secrets.AWS_DEPLOY_ROLE_ARN }}
CDEOF
fi
echo " Created ci.yaml and deploy.yaml pinned to ${WORKFLOW_VERSION}"
echo " Created ci.yaml and deploy.yaml pinned to ${WORKFLOW_VERSION}, and renovate.json"
fi
echo ""
@ -266,5 +277,6 @@ echo "=== Provisioning complete ==="
echo ""
echo "Remaining manual steps:"
echo " 1. Create any Secrets Manager secrets needed (${REPO_NAME}/secret-name)"
echo " 2. Commit the workflow files on a conventional branch"
echo " 2. Commit the workflow files and renovate.json on a conventional branch"
echo " 3. Open a PR and verify the ci / ci check passes"
echo " 4. Flip the repo from Silent to Interactive in the Mend Developer Portal when it should receive Renovate PRs"