chore(scripts): provision repos with renovate.json and no Dependabot update PRs

This commit is contained in:
Adam Moussa 2026-10-05 14:13:11 -04:00
parent efec84a07a
commit a6d0befe46
No known key found for this signature in database

View file

@ -186,26 +186,37 @@ gh secret set AWS_DEPLOY_ROLE_ARN \
echo " Secret set." echo " Secret set."
# 4. Enable security features # 4. Enable security features
# Dependabot alerts stay on. Dependabot security-update PRs are not enabled:
# Renovate opens CVE fix PRs once the repo is Interactive (github-standards.md).
echo "" echo ""
echo "[4/5] Enabling security features..." echo "[4/5] Enabling security features..."
gh api "repos/${ORG}/${REPO_NAME}/vulnerability-alerts" -X PUT 2>/dev/null || true gh api "repos/${ORG}/${REPO_NAME}/vulnerability-alerts" -X PUT 2>/dev/null || true
gh api "repos/${ORG}/${REPO_NAME}" -X PATCH \ gh api "repos/${ORG}/${REPO_NAME}" -X PATCH \
-f security_and_analysis.dependabot_security_updates.status=enabled \ -f security_and_analysis.dependabot_security_updates.status=disabled \
-f security_and_analysis.secret_scanning.status=enabled \ -f security_and_analysis.secret_scanning.status=enabled \
--silent 2>/dev/null || true --silent 2>/dev/null || true
echo " Dependabot alerts, security updates, and secret scanning enabled." echo " Dependabot alerts and secret scanning enabled; Dependabot security-update PRs off (Renovate handles them)."
# 5. Create CI/CD workflow stubs # 5. Create CI/CD workflow stubs and the Renovate config
echo "" echo ""
echo "[5/5] Creating CI/CD workflow files..." echo "[5/5] Creating CI/CD workflow files and renovate.json..."
REPO_DIR="${HOME}/Documents/repositories/${REPO_NAME}" REPO_DIR="${HOME}/Documents/repositories/${REPO_NAME}"
if [[ ! -d "${REPO_DIR}" ]]; then if [[ ! -d "${REPO_DIR}" ]]; then
echo " Repo not cloned locally — skipping workflow file creation." echo " Repo not cloned locally — skipping workflow and renovate.json creation."
echo " Clone it and re-run, or create .github/workflows/ manually." echo " Clone it and re-run, or create .github/workflows/ and renovate.json manually."
else else
mkdir -p "${REPO_DIR}/.github/workflows" mkdir -p "${REPO_DIR}/.github/workflows"
# Renovate, not Dependabot. The org preset chain is inherited from
# renovate-config; this file makes it visible in the repo.
cat > "${REPO_DIR}/renovate.json" <<'RENOVATEEOF'
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": ["local>Sea-Haven-Industries/.github"]
}
RENOVATEEOF
if [[ "$STACK_TYPE" == "cdk" ]]; then if [[ "$STACK_TYPE" == "cdk" ]]; then
cat > "${REPO_DIR}/.github/workflows/ci.yaml" <<CIEOF cat > "${REPO_DIR}/.github/workflows/ci.yaml" <<CIEOF
name: CI name: CI
@ -258,7 +269,7 @@ jobs:
deploy-role-arn: \${{ secrets.AWS_DEPLOY_ROLE_ARN }} deploy-role-arn: \${{ secrets.AWS_DEPLOY_ROLE_ARN }}
CDEOF CDEOF
fi fi
echo " Created ci.yaml and deploy.yaml pinned to ${WORKFLOW_VERSION}" echo " Created ci.yaml and deploy.yaml pinned to ${WORKFLOW_VERSION}, and renovate.json"
fi fi
echo "" echo ""
@ -266,5 +277,6 @@ echo "=== Provisioning complete ==="
echo "" echo ""
echo "Remaining manual steps:" echo "Remaining manual steps:"
echo " 1. Create any Secrets Manager secrets needed (${REPO_NAME}/secret-name)" echo " 1. Create any Secrets Manager secrets needed (${REPO_NAME}/secret-name)"
echo " 2. Commit the workflow files on a conventional branch" echo " 2. Commit the workflow files and renovate.json on a conventional branch"
echo " 3. Open a PR and verify the ci / ci check passes" echo " 3. Open a PR and verify the ci / ci check passes"
echo " 4. Flip the repo from Silent to Interactive in the Mend Developer Portal when it should receive Renovate PRs"