shoc-frontend-new/.github/renovate.json
Adam Moussa bebd517290
chore(renovate): widen the schedule, manage workflow actions, surface actionlint
The org window (before 6am on Monday) has produced only one security PR in
this repository since the overlay landed, so the overlay now opens every
weekday morning. The github-actions manager is enabled so the digest-pinned
actions in the workflows follow the org's pinning and grouping rules. A regex
manager tracks the actionlint release installed by the governance job; it is
held for dashboard approval because the SHA256 pin next to it has to be
updated by hand.
2026-09-18 18:50:49 -04:00

92 lines
3.1 KiB
JSON

{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"enabledManagers": ["npm", "custom.regex", "terraform", "github-actions"],
"schedule": ["before 6am every weekday"],
"minimumReleaseAge": "3 days",
"internalChecksFilter": "strict",
"customManagers": [
{
"customType": "regex",
"description": "Playwright image tag in CI must match @playwright/test",
"managerFilePatterns": ["/^\\.github/workflows/ci\\.ya?ml$/"],
"matchStrings": [
"mcr\\.microsoft\\.com/playwright:v(?<currentValue>\\d+\\.\\d+\\.\\d+)-noble"
],
"datasourceTemplate": "npm",
"depNameTemplate": "@playwright/test",
"versioningTemplate": "npm"
},
{
"customType": "regex",
"description": [
"actionlint release installed by the governance job; its SHA256 pin must be updated by hand, so this only surfaces the update on the dashboard"
],
"managerFilePatterns": ["/^\\.github/workflows/ci\\.ya?ml$/"],
"matchStrings": ["ACTIONLINT_VERSION: \"(?<currentValue>\\d+\\.\\d+\\.\\d+)\""],
"datasourceTemplate": "github-releases",
"depNameTemplate": "rhysd/actionlint",
"extractVersionTemplate": "^v(?<version>.*)$"
}
],
"packageRules": [
{
"description": ["Group non-major Terraform provider updates"],
"matchManagers": ["terraform"],
"matchUpdateTypes": ["minor", "patch"],
"groupName": "terraform minor and patch"
},
{
"description": ["Do not open major or replacement PRs until approved on the dashboard"],
"matchUpdateTypes": ["major", "replacement"],
"dependencyDashboardApproval": true
},
{
"description": [
"Do not open Playwright PRs until approved; image and upload-artifact share a Node runtime"
],
"matchPackageNames": ["@playwright/test"],
"dependencyDashboardApproval": true,
"groupName": "playwright"
},
{
"description": [
"Do not open actionlint PRs until approved; the SHA256 pin in ci.yaml has to change with the version"
],
"matchPackageNames": ["rhysd/actionlint"],
"dependencyDashboardApproval": true
},
{
"description": ["Keep MUI packages together"],
"matchPackageNames": ["@mui/**"],
"matchUpdateTypes": ["major"],
"groupName": "mui"
},
{
"description": ["Keep React and its type packages together"],
"matchPackageNames": ["react", "react-dom", "@types/react", "@types/react-dom"],
"matchUpdateTypes": ["major"],
"groupName": "react"
},
{
"description": ["Keep FullCalendar packages together"],
"matchPackageNames": ["@fullcalendar/**"],
"matchUpdateTypes": ["major"],
"groupName": "fullcalendar"
},
{
"description": ["Do not bump package.json engines"],
"matchDepTypes": ["engines"],
"enabled": false
},
{
"description": ["Do not bump packageManager"],
"matchDepTypes": ["packageManager"],
"enabled": false
},
{
"description": ["Keep TanStack Query packages on one version"],
"matchPackageNames": ["@tanstack/**"],
"groupName": "tanstack query"
}
]
}