Skip to content

chore: add renovate.json extending the fleet preset - #131

Merged
rubenhensen merged 1 commit into
mainfrom
renovate/add-config
Sep 24, 2026
Merged

rubenhensen merged 1 commit into
mainfrom
renovate/add-config

Conversation

@dobby-coder

@dobby-coder dobby-coder Bot commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

Closes #130.

What this does

Adds renovate.json at the repo root, extending the fleet preset from encryption4all/renovate-config (already on its main), with rangeStrategy: "bump" since this repo is an app, not a published library. No repo-specific ignore rule, per the decisions settled in encryption4all/postguard#254 and restated in #130.

Adds scripts/renovate-config.test.mjs, picked up by the existing npm test (node --test's default discovery, same as scripts/check-claude-md.test.mjs). It asserts:

  • extends includes github>encryption4all/renovate-config
  • rangeStrategy is bump
  • automerge: true never appears anywhere in the config (walked recursively, so a rule buried in packageRules can't hide it)

Proof the test is not fail-open

Before adding renovate.json, ran npm test with only the new test file in place: all three assertions failed on ENOENT (no renovate.json yet), confirming discovery finds the new file.

With the correct renovate.json committed, then reverted one at a time:

  • Added "automerge": true at the top level → red (1 failing test), reverted.
  • Dropped the extends entry → red (1 failing test), reverted.
  • No repo-specific ignore rule exists in this repo, so that proof step doesn't apply here.

Final state: npm test passes (21/21, including the pre-existing check-claude-md suite).

npx --yes --package renovate@44 -- renovate-config-validator --strict renovate.json exits 0 (with a Node 22 vs. the package's declared ^24.11.0 engine warning only — no Node 24 runtime was available in this container; the validator itself ran fine).

git diff --name-only origin/main...HEAD -- .github/workflows/ is empty. Only renovate.json and the one new test file changed.

🤖 Generated with Claude Code

Onboards this repo to the fleet's hosted Renovate app: extend
github>encryption4all/renovate-config and use rangeStrategy "bump" since
the site is an app, not a published library. No repo-specific ignore
rule, per the decisions settled in encryption4all/postguard#254.

A node --test file asserts the extends entry, the range strategy, and
that automerge: true never sneaks in anywhere in the config, so the
onboarding can't silently regress.

Part of encryption4all/postguard#247.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@dobby-coder
dobby-coder Bot requested a review from rubenhensen September 24, 2026 07:13

@dobby-coder dobby-coder Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: APPROVE (posted as COMMENT — GitHub blocks a self-approve: the reviewing identity here, dobby-coder[bot], is the same bot that authored this PR, and that holds for both the default and the org-scoped token, so no available credential can submit a native APPROVE event on this PR).

Checked against the 5 binding rules (atomic-commits, code-comments, draft-pull-requests, no-summary-issues, test-suite-before-submit) and against the findings handed off from the prior review step — clean on both.

  • atomic-commits: one commit, well-described, doing one logical thing.
  • code-comments: scripts/renovate-config.test.mjs opens with a short file-header comment and two WHY-comments (why node --test needs no dependency, why the automerge check walks the whole tree) — matches the density of its neighbour scripts/check-claude-md.test.mjs.
  • draft-pull-requests: already draft.
  • no-summary-issues: none created.
  • test-suite-before-submit: independently re-ran npm ci && npm test on the checked-out PR branch — 21/21 pass, including the 3 new tests and the pre-existing check-claude-md suite.

Also independently confirmed: no workflow files touched, and the PR's fail-open proof (dropping extends / adding top-level automerge: true) is reproducible.

No findings.

@dobby-coder
dobby-coder Bot marked this pull request as ready for review September 24, 2026 07:19
@rubenhensen
rubenhensen merged commit 908488f into main Sep 24, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

renovate: add postguard-docs's renovate.json

1 participant