drop renovate version pin and keep release-age cooldown for vulns

Unpinning the CLI keeps the previous install behavior, and leaving
minimumReleaseAge in place for vulnerabilityAlerts means a malicious
release can't be pulled in immediately.
This commit is contained in:
Madison Grubb
2026-08-13 10:29:48 -04:00
parent d771c4c97f
commit 1b88019fb9
6 changed files with 28 additions and 7711 deletions
+14 -6
View File
@@ -3,7 +3,6 @@ name: Renovate
on:
workflow_dispatch:
schedule:
# Every 6 hours is enough once deps are caught up; use workflow_dispatch to run now.
- cron: "0 */6 * * *"
jobs:
@@ -17,11 +16,20 @@ jobs:
- name: Set up Node.js
uses: https://git.keligrubb.com/actions/setup-node@v6
with:
node-version: "24"
cache: npm
node-version: '24'
- name: Install dependencies
run: npm ci
- name: Cache npm and Renovate
uses: https://git.keligrubb.com/actions/cache@v6
with:
path: |
~/.npm
~/.cache/renovate
key: renovate-${{ runner.os }}-${{ hashFiles('renovate.json') }}
restore-keys: |
renovate-${{ runner.os }}-
- name: Install Renovate
run: npm i -g renovate
- name: Run Renovate
env:
@@ -31,4 +39,4 @@ jobs:
RENOVATE_AUTODISCOVER: "true"
RENOVATE_GITHUB_COM_TOKEN: ${{ secrets.RENOVATE_GITHUB_COM_TOKEN }}
RENOVATE_CONFIG_FILE: renovate.json
run: npx renovate
run: renovate
-1
View File
@@ -1 +0,0 @@
node_modules/
+13 -13
View File
@@ -1,13 +1,13 @@
# Renovate + Gitea Actions for Gitea
This repo runs Renovate via **Gitea Actions**, currently every 6 hours. Renovate autodiscovers all Gitea repositories the bot user can access and opens PRs for dependency updates (including OSV-backed vulnerability fixes).
This repo runs [Renovate](https://docs.renovatebot.com/) via **Gitea Actions**, currently every 6 hours. Renovate autodiscovers all Gitea repositories the bot user can access and opens PRs for dependency updates.
## How it works
* **Gitea Actions** runs a single job from `.gitea/workflows/renovate.yml` on a **cron schedule** and on **manual dispatch**.
* The job installs a **pinned** `renovate` from `package.json` / `package-lock.json` and runs it with config from **renovate.json**.
* Renovate processes every non-mirror Gitea repo the bot token can access (push/pull, PRs enabled), opening and updating PRs. Minor and patch updates are grouped into one PR per repo; major updates use separate PRs.
* Known vulnerable packages get prioritized PRs labeled `security` and skip the normal release-age wait.
- **Gitea Actions** runs a single job from `.gitea/workflows/renovate.yml` on a **cron schedule** and on **manual dispatch**.
- The job uses the official `renovatebot/github-action` and reads config from **renovate.json** in this repo.
- Renovate processes every non-mirror Gitea repo the bot token can access (push/pull, PRs enabled), opening and updating PRs. Minor and patch updates are grouped into one PR per repo; major updates use separate PRs.
- Dependencies with known OSV vulnerabilities get their own PRs labeled `security`. They still wait out `minimumReleaseAge` like everything else, so a poisoned release can't land instantly.
## Setup
@@ -29,11 +29,11 @@ To change the schedule (e.g. daily or weekly), edit the cron expression there an
Configure these **repository** or **organization** secrets in Gitea:
| Secret | Required | Description |
| --- | --- | --- |
|--------|----------|-------------|
| `RENOVATE_TOKEN` | Yes | Gitea Personal Access Token (PAT) for the bot account |
| `RENOVATE_GITHUB_COM_TOKEN` | No | **Recommended.** Read-only GitHub PAT so Renovate can fetch changelogs and release notes without hitting anonymous rate limits. Create at [GitHub → Settings → Developer settings → Personal access tokens](https://github.com/settings/tokens) with scope `read:packages` (or no scopes for public data). If you dont want GitHub integration, remove the `RENOVATE_GITHUB_COM_TOKEN` lines from [`.gitea/workflows/renovate.yml`](./.gitea/workflows/renovate.yml). |
| `RENOVATE_GITHUB_COM_TOKEN` | No | **Recommended.** Read-only GitHub PAT so Renovate can fetch changelogs and release notes without hitting anonymous rate limits. Create at [GitHub → Settings → Developer settings → Personal access tokens](https://github.com/settings/tokens) with scope `read:packages` (or no scopes for public data). If you dont want GitHub integration, remove the `RENOVATE_GITHUB_COM_TOKEN` lines from [.gitea/workflows/renovate.yml](.gitea/workflows/renovate.yml). |
The Gitea endpoint (`RENOVATE_ENDPOINT`) is set in `.gitea/workflows/renovate.yml`; change it there if your instance has a different URL. The workflow passes `RENOVATE_GITHUB_COM_TOKEN` to Renovate when the secret is set.
The Gitea endpoint (`RENOVATE_ENDPOINT`) is set in [.gitea/workflows/renovate.yml](.gitea/workflows/renovate.yml); change it there if your instance has a different URL. The workflow passes `RENOVATE_GITHUB_COM_TOKEN` to Renovate when the secret is set.
### 3. Gitea Personal Access Token (PAT)
@@ -46,18 +46,18 @@ Create a dedicated Renovate bot user in Gitea (or your IdP) so PRs and commits a
### 4. Labels
Create these labels on repos (or org-wide) so Renovate can apply them:
Create these labels on the repos (or org-wide) so Renovate can apply them:
* `dependencies`normal update PRs
* `security` — vulnerability-driven PRs
- `dependencies` — all update PRs
- `security` — vulnerability-driven PRs
## Configuration
Renovate is configured in **renovate.json**. It sets the platform, autodiscovery, grouping (`group:allNonMajor`), best-practices-ish presets, OSV vulnerability alerts, abandonment reporting, PR rate limits, and disables the Dependency Dashboard via the `:disableDependencyDashboard` preset (so it stays off even if other presets enable it). Token and endpoint are provided only via environment (secrets).
Renovate is configured in **renovate.json**. It sets the platform, autodiscovery, grouping (`group:allNonMajor`), best-practices presets, OSV vulnerability alerts, abandoned-package reporting, PR rate limits, and disables the Dependency Dashboard via the `:disableDependencyDashboard` preset (so it stays off even if other presets enable it). Token and endpoint are provided only via environment (secrets).
**Target repos:** If a repo has its own **renovate.json**, it is merged on top of this global config. A repo that sets its own `extends` (e.g. `"extends": ["config:recommended"]`) can effectively replace the global presets, lose grouping, or re-enable the dashboard. To keep bundled PRs and no dashboard, either omit per-repo configs or ensure they do not override `extends` / dashboard settings.
The workflow pins Renovate via npm so runs are reproducible; Renovate can open PRs against this repo to bump its own `renovate` dependency.
The workflow uses the official **renovatebot/github-action**, which runs the Renovate CLI with a full feature set, suitable for lock file updates (e.g. `package-lock.json`) and common package managers.
## Narrowing scope
-7681
View File
File diff suppressed because it is too large Load Diff
-8
View File
@@ -1,8 +0,0 @@
{
"name": "renovate-runner",
"private": true,
"description": "Runs Renovate against git.keligrubb.com via Gitea Actions",
"dependencies": {
"renovate": "44.28.0"
}
}
+1 -2
View File
@@ -17,8 +17,7 @@
"osvVulnerabilityAlerts": true,
"vulnerabilityAlerts": {
"enabled": true,
"labels": ["security", "dependencies"],
"minimumReleaseAge": "0 days"
"labels": ["security", "dependencies"]
},
"prConcurrentLimit": 5,
"prHourlyLimit": 5,