From e90e51d271a59541c0e1f7a29296b0e20a97a54e Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Wed, 26 Aug 2026 17:58:31 -0400 Subject: [PATCH] chore(renovate): add frontend overlay with three-day release age (#90) * chore(renovate): add Renovate frontend overlay config * chore: remove dependabot.yml config * fix: add `github-actions` to `enabledManagers` With the removal of this repositories `dependabot.yml`, a lack of `github-actions` within the config would leave a coverage gap on `actions/checkout`, `actions/setup-dotnet`, `actions/setup-node`, etc. * fix(renovate): annotate pinned actions --------- Co-authored-by: Alexandre Brandizzi --- .github/dependabot.yml | 13 -------- .github/renovate.json | 61 ++++++++++++++++++++++++++++++++++++ .github/workflows/deploy.yml | 21 +++++-------- 3 files changed, 68 insertions(+), 27 deletions(-) delete mode 100644 .github/dependabot.yml create mode 100644 .github/renovate.json diff --git a/.github/dependabot.yml b/.github/dependabot.yml deleted file mode 100644 index 1637baf..0000000 --- a/.github/dependabot.yml +++ /dev/null @@ -1,13 +0,0 @@ -version: 2 -updates: - - package-ecosystem: github-actions - directory: / - schedule: - interval: weekly - open-pull-requests-limit: 5 - - - package-ecosystem: npm - directory: /infra/cdk - schedule: - interval: weekly - open-pull-requests-limit: 5 diff --git a/.github/renovate.json b/.github/renovate.json new file mode 100644 index 0000000..45e395d --- /dev/null +++ b/.github/renovate.json @@ -0,0 +1,61 @@ +{ + "$schema": "https://docs.renovatebot.com/renovate-schema.json", + "enabledManagers": ["nuget", "npm", "github-actions"], + "minimumReleaseAge": "3 days", + "internalChecksFilter": "strict", + "packageRules": [ + { + "description": [ + "Do not open major or replacement PRs until approved on the dashboard" + ], + "matchUpdateTypes": ["major", "replacement"], + "dependencyDashboardApproval": true + }, + { + "description": ["Group non-major nuget updates"], + "matchManagers": ["nuget"], + "matchUpdateTypes": ["minor", "patch"], + "groupName": "nuget minor and patch" + }, + { + "description": [ + "Keep ASP.NET Core, EF Core, and dotnet-ef majors together" + ], + "matchPackageNames": [ + "Microsoft.AspNetCore{/,}**", + "Microsoft.EntityFrameworkCore{/,}**", + "dotnet-ef" + ], + "matchUpdateTypes": ["major"], + "groupName": "aspnetcore and ef core" + }, + { + "description": ["Keep AWS SDK majors together"], + "matchPackageNames": ["/^AWSSDK\\./"], + "matchUpdateTypes": ["major"], + "groupName": "aws sdk" + }, + { + "description": ["Keep xunit and the VS test SDK together"], + "matchPackageNames": [ + "xunit", + "xunit.{/,}**", + "Microsoft.NET.Test.Sdk" + ], + "matchUpdateTypes": ["major"], + "groupName": "xunit" + }, + { + "description": ["Keep FluentValidation packages together"], + "matchPackageNames": ["FluentValidation{/,}**"], + "matchUpdateTypes": ["major"], + "groupName": "fluentvalidation" + }, + { + "description": ["Keep aws-cdk and aws-cdk-lib together"], + "matchPackageNames": ["aws-cdk", "aws-cdk-lib"], + "matchUpdateTypes": ["major"], + "groupName": "aws cdk" + } + ] +} \ No newline at end of file diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 714cac3..5981e3a 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -16,20 +16,17 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - # actions/checkout @ v7.0.1 - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 - name: Set up .NET - # actions/setup-dotnet @ v6.0.0 - uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 + uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0 with: dotnet-version: "8.0.x" - name: Set up Node.js - # actions/setup-node @ v6.5.0 - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: "22.22.1" cache: npm @@ -83,12 +80,10 @@ jobs: cancel-in-progress: false steps: - name: Checkout - # actions/checkout @ v7.0.1 - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Set up .NET - # actions/setup-dotnet @ v6.0.0 - uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 + uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0 with: dotnet-version: "8.0.x" @@ -96,8 +91,7 @@ jobs: run: bash scripts/package-elastic-beanstalk.sh - name: Configure AWS credentials (OIDC) - # aws-actions/configure-aws-credentials @ v6.2.3 - uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c + uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3 with: role-to-assume: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} aws-region: us-east-1 @@ -115,8 +109,7 @@ jobs: echo "Previous version label: $prev" - name: Deploy prebuilt bundle to existing environment - # aws-actions/aws-elasticbeanstalk-deploy @ v1.0.6 - uses: aws-actions/aws-elasticbeanstalk-deploy@7883cdd454c162051bf6fc13389536b045149b4c + uses: aws-actions/aws-elasticbeanstalk-deploy@7883cdd454c162051bf6fc13389536b045149b4c # v1.0.8 with: aws-region: us-east-1 application-name: shoc-backend