From a6d0befe46928ab3c33ef99b0d92cbb9a6edb420 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Mon, 5 Oct 2026 14:13:11 -0400 Subject: [PATCH] chore(scripts): provision repos with renovate.json and no Dependabot update PRs --- scripts/provision-repo.sh | 28 ++++++++++++++++++++-------- 1 file changed, 20 insertions(+), 8 deletions(-) diff --git a/scripts/provision-repo.sh b/scripts/provision-repo.sh index 8834fb3..03f8dbd 100755 --- a/scripts/provision-repo.sh +++ b/scripts/provision-repo.sh @@ -186,26 +186,37 @@ gh secret set AWS_DEPLOY_ROLE_ARN \ echo " Secret set." # 4. Enable security features +# Dependabot alerts stay on. Dependabot security-update PRs are not enabled: +# Renovate opens CVE fix PRs once the repo is Interactive (github-standards.md). echo "" echo "[4/5] Enabling security features..." gh api "repos/${ORG}/${REPO_NAME}/vulnerability-alerts" -X PUT 2>/dev/null || true gh api "repos/${ORG}/${REPO_NAME}" -X PATCH \ - -f security_and_analysis.dependabot_security_updates.status=enabled \ + -f security_and_analysis.dependabot_security_updates.status=disabled \ -f security_and_analysis.secret_scanning.status=enabled \ --silent 2>/dev/null || true -echo " Dependabot alerts, security updates, and secret scanning enabled." +echo " Dependabot alerts and secret scanning enabled; Dependabot security-update PRs off (Renovate handles them)." -# 5. Create CI/CD workflow stubs +# 5. Create CI/CD workflow stubs and the Renovate config echo "" -echo "[5/5] Creating CI/CD workflow files..." +echo "[5/5] Creating CI/CD workflow files and renovate.json..." REPO_DIR="${HOME}/Documents/repositories/${REPO_NAME}" if [[ ! -d "${REPO_DIR}" ]]; then - echo " Repo not cloned locally — skipping workflow file creation." - echo " Clone it and re-run, or create .github/workflows/ manually." + echo " Repo not cloned locally — skipping workflow and renovate.json creation." + echo " Clone it and re-run, or create .github/workflows/ and renovate.json manually." else mkdir -p "${REPO_DIR}/.github/workflows" + # Renovate, not Dependabot. The org preset chain is inherited from + # renovate-config; this file makes it visible in the repo. + cat > "${REPO_DIR}/renovate.json" <<'RENOVATEEOF' +{ + "$schema": "https://docs.renovatebot.com/renovate-schema.json", + "extends": ["local>Sea-Haven-Industries/.github"] +} +RENOVATEEOF + if [[ "$STACK_TYPE" == "cdk" ]]; then cat > "${REPO_DIR}/.github/workflows/ci.yaml" <