mirror of
https://github.com/Sea-Haven-Industries/engineering-handbook.git
synced 2026-10-07 13:59:03 +00:00
chore(scripts): provision repos with renovate.json and no Dependabot update PRs
This commit is contained in:
parent
efec84a07a
commit
a6d0befe46
1 changed files with 20 additions and 8 deletions
|
|
@ -186,26 +186,37 @@ gh secret set AWS_DEPLOY_ROLE_ARN \
|
||||||
echo " Secret set."
|
echo " Secret set."
|
||||||
|
|
||||||
# 4. Enable security features
|
# 4. Enable security features
|
||||||
|
# Dependabot alerts stay on. Dependabot security-update PRs are not enabled:
|
||||||
|
# Renovate opens CVE fix PRs once the repo is Interactive (github-standards.md).
|
||||||
echo ""
|
echo ""
|
||||||
echo "[4/5] Enabling security features..."
|
echo "[4/5] Enabling security features..."
|
||||||
gh api "repos/${ORG}/${REPO_NAME}/vulnerability-alerts" -X PUT 2>/dev/null || true
|
gh api "repos/${ORG}/${REPO_NAME}/vulnerability-alerts" -X PUT 2>/dev/null || true
|
||||||
gh api "repos/${ORG}/${REPO_NAME}" -X PATCH \
|
gh api "repos/${ORG}/${REPO_NAME}" -X PATCH \
|
||||||
-f security_and_analysis.dependabot_security_updates.status=enabled \
|
-f security_and_analysis.dependabot_security_updates.status=disabled \
|
||||||
-f security_and_analysis.secret_scanning.status=enabled \
|
-f security_and_analysis.secret_scanning.status=enabled \
|
||||||
--silent 2>/dev/null || true
|
--silent 2>/dev/null || true
|
||||||
echo " Dependabot alerts, security updates, and secret scanning enabled."
|
echo " Dependabot alerts and secret scanning enabled; Dependabot security-update PRs off (Renovate handles them)."
|
||||||
|
|
||||||
# 5. Create CI/CD workflow stubs
|
# 5. Create CI/CD workflow stubs and the Renovate config
|
||||||
echo ""
|
echo ""
|
||||||
echo "[5/5] Creating CI/CD workflow files..."
|
echo "[5/5] Creating CI/CD workflow files and renovate.json..."
|
||||||
|
|
||||||
REPO_DIR="${HOME}/Documents/repositories/${REPO_NAME}"
|
REPO_DIR="${HOME}/Documents/repositories/${REPO_NAME}"
|
||||||
if [[ ! -d "${REPO_DIR}" ]]; then
|
if [[ ! -d "${REPO_DIR}" ]]; then
|
||||||
echo " Repo not cloned locally — skipping workflow file creation."
|
echo " Repo not cloned locally — skipping workflow and renovate.json creation."
|
||||||
echo " Clone it and re-run, or create .github/workflows/ manually."
|
echo " Clone it and re-run, or create .github/workflows/ and renovate.json manually."
|
||||||
else
|
else
|
||||||
mkdir -p "${REPO_DIR}/.github/workflows"
|
mkdir -p "${REPO_DIR}/.github/workflows"
|
||||||
|
|
||||||
|
# Renovate, not Dependabot. The org preset chain is inherited from
|
||||||
|
# renovate-config; this file makes it visible in the repo.
|
||||||
|
cat > "${REPO_DIR}/renovate.json" <<'RENOVATEEOF'
|
||||||
|
{
|
||||||
|
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
||||||
|
"extends": ["local>Sea-Haven-Industries/.github"]
|
||||||
|
}
|
||||||
|
RENOVATEEOF
|
||||||
|
|
||||||
if [[ "$STACK_TYPE" == "cdk" ]]; then
|
if [[ "$STACK_TYPE" == "cdk" ]]; then
|
||||||
cat > "${REPO_DIR}/.github/workflows/ci.yaml" <<CIEOF
|
cat > "${REPO_DIR}/.github/workflows/ci.yaml" <<CIEOF
|
||||||
name: CI
|
name: CI
|
||||||
|
|
@ -258,7 +269,7 @@ jobs:
|
||||||
deploy-role-arn: \${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
deploy-role-arn: \${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
||||||
CDEOF
|
CDEOF
|
||||||
fi
|
fi
|
||||||
echo " Created ci.yaml and deploy.yaml pinned to ${WORKFLOW_VERSION}"
|
echo " Created ci.yaml and deploy.yaml pinned to ${WORKFLOW_VERSION}, and renovate.json"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
echo ""
|
echo ""
|
||||||
|
|
@ -266,5 +277,6 @@ echo "=== Provisioning complete ==="
|
||||||
echo ""
|
echo ""
|
||||||
echo "Remaining manual steps:"
|
echo "Remaining manual steps:"
|
||||||
echo " 1. Create any Secrets Manager secrets needed (${REPO_NAME}/secret-name)"
|
echo " 1. Create any Secrets Manager secrets needed (${REPO_NAME}/secret-name)"
|
||||||
echo " 2. Commit the workflow files on a conventional branch"
|
echo " 2. Commit the workflow files and renovate.json on a conventional branch"
|
||||||
echo " 3. Open a PR and verify the ci / ci check passes"
|
echo " 3. Open a PR and verify the ci / ci check passes"
|
||||||
|
echo " 4. Flip the repo from Silent to Interactive in the Mend Developer Portal when it should receive Renovate PRs"
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue