chore: add renovate.json extending the fleet preset - #131
Merged
Merged
Conversation
Onboards this repo to the fleet's hosted Renovate app: extend github>encryption4all/renovate-config and use rangeStrategy "bump" since the site is an app, not a published library. No repo-specific ignore rule, per the decisions settled in encryption4all/postguard#254. A node --test file asserts the extends entry, the range strategy, and that automerge: true never sneaks in anywhere in the config, so the onboarding can't silently regress. Part of encryption4all/postguard#247. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Contributor
Author
There was a problem hiding this comment.
Verdict: APPROVE (posted as COMMENT — GitHub blocks a self-approve: the reviewing identity here, dobby-coder[bot], is the same bot that authored this PR, and that holds for both the default and the org-scoped token, so no available credential can submit a native APPROVE event on this PR).
Checked against the 5 binding rules (atomic-commits, code-comments, draft-pull-requests, no-summary-issues, test-suite-before-submit) and against the findings handed off from the prior review step — clean on both.
- atomic-commits: one commit, well-described, doing one logical thing.
- code-comments:
scripts/renovate-config.test.mjsopens with a short file-header comment and two WHY-comments (whynode --testneeds no dependency, why theautomergecheck walks the whole tree) — matches the density of its neighbourscripts/check-claude-md.test.mjs. - draft-pull-requests: already draft.
- no-summary-issues: none created.
- test-suite-before-submit: independently re-ran
npm ci && npm teston the checked-out PR branch — 21/21 pass, including the 3 new tests and the pre-existingcheck-claude-mdsuite.
Also independently confirmed: no workflow files touched, and the PR's fail-open proof (dropping extends / adding top-level automerge: true) is reproducible.
No findings.
rubenhensen
approved these changes
Sep 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #130.
What this does
Adds
renovate.jsonat the repo root, extending the fleet preset fromencryption4all/renovate-config(already on itsmain), withrangeStrategy: "bump"since this repo is an app, not a published library. No repo-specific ignore rule, per the decisions settled in encryption4all/postguard#254 and restated in #130.Adds
scripts/renovate-config.test.mjs, picked up by the existingnpm test(node --test's default discovery, same asscripts/check-claude-md.test.mjs). It asserts:extendsincludesgithub>encryption4all/renovate-configrangeStrategyisbumpautomerge: truenever appears anywhere in the config (walked recursively, so a rule buried inpackageRulescan't hide it)Proof the test is not fail-open
Before adding
renovate.json, rannpm testwith only the new test file in place: all three assertions failed onENOENT(norenovate.jsonyet), confirming discovery finds the new file.With the correct
renovate.jsoncommitted, then reverted one at a time:"automerge": trueat the top level → red (1 failing test), reverted.extendsentry → red (1 failing test), reverted.Final state:
npm testpasses (21/21, including the pre-existingcheck-claude-mdsuite).npx --yes --package renovate@44 -- renovate-config-validator --strict renovate.jsonexits0(with a Node 22 vs. the package's declared^24.11.0engine warning only — no Node 24 runtime was available in this container; the validator itself ran fine).git diff --name-only origin/main...HEAD -- .github/workflows/is empty. Onlyrenovate.jsonand the one new test file changed.🤖 Generated with Claude Code