Skip to content

[Feat]: Configure Renovate for automatic dependency updates #22

Description

@Norbiros

Tip

This issue is not about shipping the quickest or easiest solution.

Take time to research the problem, explore alternatives, discuss the approach with @Norbiros and the team, and implement a solution you can confidently defend in code review.

Task

Configure automatic dependency updates for npm packages, GitHub Actions, and Dockerfiles. Our preferred tool for this is Mend Renovate, since it has many useful features and integrations.

Possible considerations:

  • Is Renovate the best choice?
  • Should we use .json, .json5, or .jsonc?
  • Can we improve security so we do not miss important updates, while still keeping a minimum release age of 1 day?
  • What is the best strategy: pinning, bumping, or something else?

Taking it a step further:

  • Backport it to https://github.com/Zerya-Dev/starters
  • Create a unified configuration, preferably in .github, so we can reuse the same config across all repositories, similar to how Nuxt does it. Reusing configuration is better than copying it over and over.
  • Configure all projects to use pinned GitHub Actions versions and make this required at the organization level.

Other, pre-existing solutions

Do not copy this 1:1. The goal is to find something better and learn from the process.

From motoq:

// renovate.jsonc

{
  "$schema": "https://docs.renovatebot.com/renovate-schema.json",
  "timezone": "Europe/Warsaw",
  "rangeStrategy": "bump",
  "extends": [
    "config:recommended",
    "group:allNonMajor",
    ":semanticCommitTypeAll(chore)",
    "workarounds:all"
  ],
  "dependencyDashboard": false,
  "labels": ["dependencies"],
  "lockFileMaintenance": {
    "enabled": true,
    "schedule": ["before 6am on Monday"]
  },
  "ignorePaths": [
    // This directory is mirrored from https://github.com/CIRFMF/ksef-pdf-generator.
    // Renovate should not update it here to avoid conflicts with upstream changes.
    "backend/MOTOQ.Infrastructure/Lib/ksef-pdf-generator/**"
  ],
  "vulnerabilityAlerts": {
    "schedule": ["at any time"],
    "labels": ["dependencies", "security"]
  },
  "packageRules": [
    {
      "groupName": "Frontend dependencies",
      "matchManagers": ["npm", "nodenv"],
      "minimumReleaseAge": "1 day",
      "internalChecksFilter": "strict"
    },
    {
      "groupName": ".NET dependencies",
      "matchManagers": ["nuget"],
      "minimumReleaseAge": "1 day"
    },
    {
      "groupName": "GitHub Actions",
      "matchManagers": ["github-actions"],
      "pinDigests": true,
      "schedule": ["before 6am on Monday"]
    }
  ]
}

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Fields

Issue Status

None yet

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions