Skip to content

Centralize dependency-update policy with shared Renovate presets (per-repo overrides) #345

Description

@Shinrai

Problem

Dependabot has no shared configuration: no extends, no org-wide dependabot.yml. Every repo carries its own copy of .github/dependabot.yml, seeded from the dependabot.yml template. A policy that should apply everywhere has to be swept into each repo and then drifts.

The case that surfaced this: TypeScript 7.0 breaks coverage measurement, so every repo needs to ignore 7.0.x while still accepting 7.1, which is planned to fix it (wisp#21 carries the ignore for wisp today). Most other org configuration is centrally controlled with per-repo overrides, and dependency policy is the exception.

Proposal

Move dependency updates to Renovate. The hosted Mend Renovate GitHub app is free for public and private repositories (free tier: one concurrent job on a four-hour cycle), and self-hosting is also free.

  • One shared preset in this repo (for example renovate.json or default.json, consumed as github>CLDMV/.github) holds the org policy: schedule, target-branch (next), commit prefix, labels, the vitest-family grouping, and package rules such as the TypeScript 7.0.x ignore.
  • Each repo's renovate.json is {"extends": ["github>CLDMV/.github"]} plus only its own overrides.
  • A policy change lands once in the preset and reaches every repo without a sweep.

What changes in the v4 flow

The flow is built around Dependabot, so this is a migration, not a config swap:

  • dependabot-auto-merge and its action key off Dependabot's actor and metadata.
  • dependabot-recreate uses Dependabot's @dependabot recreate command.
  • The security-PR redirect to hotfixes (redirect-hotfix-pr, described in release-flow-v4.md) detects a Dependabot PR whose base differs from the configured routine target-branch. Renovate needs an equivalent: vulnerability-alert PRs routed to hotfixes through vulnerabilityAlerts and packageRules base-branch settings.
  • Bot-PR handling elsewhere (skipping bot-created PRs, the ! deps → next labelling, feature-pr.yml) assumes Dependabot branch and author names.
  • The dependabot.yml template and the v4-bootstrap onboarding step need Renovate equivalents, and the repo-onboarding docs need updating.
  • Existing Dependabot configs and open Dependabot PRs need a cutover plan per repo.

Open questions

  • Hosted Mend app versus a self-hosted Renovate run in our own workflows (the hosted free tier's four-hour cycle and single job may matter at fleet size).
  • How Renovate's vulnerability PRs relate to GitHub Dependabot alerts and security updates, and whether to keep Dependabot security updates enabled alongside Renovate.
  • Whether the bot identity needs to be the existing cldmv-bot app for signing and auto-merge, or whether Renovate's own identity is acceptable.

Out of scope for now

Not being started yet. The fix-headers and @cldmv/configs fleet rollout comes first. Until then, the per-repo dependabot.yml ignore stays as is.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority: mediumShould be addressed in the normal course of developmentstatus: not startedNot implemented yet — no code exists for thistype: ciChanges to CI workflows, actions, or build pipelinestype: dependenciesRelates to dependency updates, version bumps, or package managementtype: enhancementAn improvement to existing functionality without adding a new feature

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions