From bebd5172901f12dac3ca5b9289430eb596ff2603 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Fri, 18 Sep 2026 18:50:49 -0400 Subject: [PATCH] chore(renovate): widen the schedule, manage workflow actions, surface actionlint The org window (before 6am on Monday) has produced only one security PR in this repository since the overlay landed, so the overlay now opens every weekday morning. The github-actions manager is enabled so the digest-pinned actions in the workflows follow the org's pinning and grouping rules. A regex manager tracks the actionlint release installed by the governance job; it is held for dashboard approval because the SHA256 pin next to it has to be updated by hand. --- .github/renovate.json | 21 ++++++++++++++++++++- 1 file changed, 20 insertions(+), 1 deletion(-) diff --git a/.github/renovate.json b/.github/renovate.json index 38bd081a..5778715b 100644 --- a/.github/renovate.json +++ b/.github/renovate.json @@ -1,6 +1,7 @@ { "$schema": "https://docs.renovatebot.com/renovate-schema.json", - "enabledManagers": ["npm", "custom.regex", "terraform"], + "enabledManagers": ["npm", "custom.regex", "terraform", "github-actions"], + "schedule": ["before 6am every weekday"], "minimumReleaseAge": "3 days", "internalChecksFilter": "strict", "customManagers": [ @@ -14,6 +15,17 @@ "datasourceTemplate": "npm", "depNameTemplate": "@playwright/test", "versioningTemplate": "npm" + }, + { + "customType": "regex", + "description": [ + "actionlint release installed by the governance job; its SHA256 pin must be updated by hand, so this only surfaces the update on the dashboard" + ], + "managerFilePatterns": ["/^\\.github/workflows/ci\\.ya?ml$/"], + "matchStrings": ["ACTIONLINT_VERSION: \"(?\\d+\\.\\d+\\.\\d+)\""], + "datasourceTemplate": "github-releases", + "depNameTemplate": "rhysd/actionlint", + "extractVersionTemplate": "^v(?.*)$" } ], "packageRules": [ @@ -36,6 +48,13 @@ "dependencyDashboardApproval": true, "groupName": "playwright" }, + { + "description": [ + "Do not open actionlint PRs until approved; the SHA256 pin in ci.yaml has to change with the version" + ], + "matchPackageNames": ["rhysd/actionlint"], + "dependencyDashboardApproval": true + }, { "description": ["Keep MUI packages together"], "matchPackageNames": ["@mui/**"],