Files
plex-playlist/renovate.json

119 lines
4.6 KiB
JSON
Raw Normal View History

{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": [
"config:recommended",
":dependencyDashboard",
":semanticCommits",
":separatePatchReleases"
],
"timezone": "America/New_York",
"schedule": ["before 9am every weekday"],
"prConcurrentLimit": 5,
"branchConcurrentLimit": 10,
"prHourlyLimit": 2,
"configMigration": false,
Stabilize self-hosted CI workflows and resolve issue #62 (#73) ## Summary Hardens CI workflows for self-hosted Gitea runners by stabilizing E2E execution and Renovate behavior across internal/external network paths. Closes #62 ## What Changed ### E2E workflow reliability - Fixed E2E workspace handoff to ensure expected repository contents are present during test execution. - Added stricter preflight checks for required frontend files before running E2E. - Reduced mount/path fragility while preserving runtime image pull and compose flow. ### Renovate workflow hardening - Added internal-first endpoint reachability selection with fallback handling. - Added token preflight checks for repository access. - Added explicit host-rule auth handling for API/git paths. - Added container-level connectivity preflight diagnostics. - Added git URL override aligned with selected endpoint context. - Removed incorrect forced Dogar host-IP pinning that broke HTTPS clone routing. ## Why CI behavior was sensitive to runner networking and Renovate clone/auth interactions. These changes make the workflow deterministic in our runner topology and address recurring CI failures. ## Scope - Workflow logic only (`cicd.yaml`, `renovate.yml`) - No app feature or API behavior changes ## Validation - Workflow YAML validation passed during updates. - Changes were applied and verified iteratively from real failing run diagnostics. Co-authored-by: copilotcoder <copilotcoder@darkhelm.org> Reviewed-on: https://dogar.darkhelm.org/DarkHelm.org/plex-playlist/pulls/73
2026-07-13 11:16:16 -04:00
"enabledManagers": [
"docker-compose",
"dockerfile",
"github-actions",
"npm",
2026-07-14 07:55:01 -04:00
"pep621"
Stabilize self-hosted CI workflows and resolve issue #62 (#73) ## Summary Hardens CI workflows for self-hosted Gitea runners by stabilizing E2E execution and Renovate behavior across internal/external network paths. Closes #62 ## What Changed ### E2E workflow reliability - Fixed E2E workspace handoff to ensure expected repository contents are present during test execution. - Added stricter preflight checks for required frontend files before running E2E. - Reduced mount/path fragility while preserving runtime image pull and compose flow. ### Renovate workflow hardening - Added internal-first endpoint reachability selection with fallback handling. - Added token preflight checks for repository access. - Added explicit host-rule auth handling for API/git paths. - Added container-level connectivity preflight diagnostics. - Added git URL override aligned with selected endpoint context. - Removed incorrect forced Dogar host-IP pinning that broke HTTPS clone routing. ## Why CI behavior was sensitive to runner networking and Renovate clone/auth interactions. These changes make the workflow deterministic in our runner topology and address recurring CI failures. ## Scope - Workflow logic only (`cicd.yaml`, `renovate.yml`) - No app feature or API behavior changes ## Validation - Workflow YAML validation passed during updates. - Changes were applied and verified iteratively from real failing run diagnostics. Co-authored-by: copilotcoder <copilotcoder@darkhelm.org> Reviewed-on: https://dogar.darkhelm.org/DarkHelm.org/plex-playlist/pulls/73
2026-07-13 11:16:16 -04:00
],
"packageRules": [
{
"description": "Automerge non-major updates for high-confidence packages",
"matchUpdateTypes": ["minor", "patch", "pin", "digest"],
"matchPackageNames": [
"/^@types//",
"/^eslint/",
"/^prettier/",
"/^ruff/",
"/^pytest/"
],
"automerge": true,
"automergeType": "branch"
},
{
"description": "Group Python dev tools updates",
Stabilize self-hosted CI workflows and resolve issue #62 (#73) ## Summary Hardens CI workflows for self-hosted Gitea runners by stabilizing E2E execution and Renovate behavior across internal/external network paths. Closes #62 ## What Changed ### E2E workflow reliability - Fixed E2E workspace handoff to ensure expected repository contents are present during test execution. - Added stricter preflight checks for required frontend files before running E2E. - Reduced mount/path fragility while preserving runtime image pull and compose flow. ### Renovate workflow hardening - Added internal-first endpoint reachability selection with fallback handling. - Added token preflight checks for repository access. - Added explicit host-rule auth handling for API/git paths. - Added container-level connectivity preflight diagnostics. - Added git URL override aligned with selected endpoint context. - Removed incorrect forced Dogar host-IP pinning that broke HTTPS clone routing. ## Why CI behavior was sensitive to runner networking and Renovate clone/auth interactions. These changes make the workflow deterministic in our runner topology and address recurring CI failures. ## Scope - Workflow logic only (`cicd.yaml`, `renovate.yml`) - No app feature or API behavior changes ## Validation - Workflow YAML validation passed during updates. - Changes were applied and verified iteratively from real failing run diagnostics. Co-authored-by: copilotcoder <copilotcoder@darkhelm.org> Reviewed-on: https://dogar.darkhelm.org/DarkHelm.org/plex-playlist/pulls/73
2026-07-13 11:16:16 -04:00
"matchManagers": ["pep621"],
"matchCategories": ["python"],
Stabilize self-hosted CI workflows and resolve issue #62 (#73) ## Summary Hardens CI workflows for self-hosted Gitea runners by stabilizing E2E execution and Renovate behavior across internal/external network paths. Closes #62 ## What Changed ### E2E workflow reliability - Fixed E2E workspace handoff to ensure expected repository contents are present during test execution. - Added stricter preflight checks for required frontend files before running E2E. - Reduced mount/path fragility while preserving runtime image pull and compose flow. ### Renovate workflow hardening - Added internal-first endpoint reachability selection with fallback handling. - Added token preflight checks for repository access. - Added explicit host-rule auth handling for API/git paths. - Added container-level connectivity preflight diagnostics. - Added git URL override aligned with selected endpoint context. - Removed incorrect forced Dogar host-IP pinning that broke HTTPS clone routing. ## Why CI behavior was sensitive to runner networking and Renovate clone/auth interactions. These changes make the workflow deterministic in our runner topology and address recurring CI failures. ## Scope - Workflow logic only (`cicd.yaml`, `renovate.yml`) - No app feature or API behavior changes ## Validation - Workflow YAML validation passed during updates. - Changes were applied and verified iteratively from real failing run diagnostics. Co-authored-by: copilotcoder <copilotcoder@darkhelm.org> Reviewed-on: https://dogar.darkhelm.org/DarkHelm.org/plex-playlist/pulls/73
2026-07-13 11:16:16 -04:00
"matchPackageNames": [
"ruff",
"pyright",
"pydoclint",
"pytest",
"pytest-asyncio",
"pytest-cov",
"pytest-mock",
"pre-commit",
"pyyaml",
"yamllint",
"toml-sort",
"language-formatters-pre-commit-hooks",
"xdoctest",
"poethepoet"
],
"groupName": "Python dev tools",
"schedule": ["before 9am on monday"]
},
{
"description": "Group Frontend dev tools updates",
"matchManagers": ["npm"],
"matchDepTypes": ["devDependencies"],
"matchPackageNames": [
"/^@typescript-eslint//",
"/^eslint/",
"/^prettier/",
"/^vite/",
"/^vitest/",
"/^playwright/"
],
"groupName": "Frontend dev tools",
"schedule": ["before 9am on monday"]
},
{
"description": "Group Docker base image updates",
"matchManagers": ["dockerfile"],
"matchPackageNames": ["ubuntu", "node", "python"],
"groupName": "Docker base images",
"schedule": ["before 9am on monday"],
"automerge": false,
"reviewersFromCodeOwners": true
},
{
"description": "Security updates - high priority",
"matchPackageNames": ["/.*/"],
"vulnerabilityAlerts": { "enabled": true },
"prPriority": 10,
"automerge": false,
"labels": ["security"],
"reviewersFromCodeOwners": true
},
{
"description": "Major updates - require manual review",
"matchUpdateTypes": ["major"],
"automerge": false,
"labels": ["major-update"],
"prPriority": 5,
"reviewersFromCodeOwners": true
feat: integrate security audits into pre-commit and CI/CD with backend pip-audit migration (#74) ## Summary This PR integrates security-focused checks into the existing quality gates and aligns local workflows with CI/CD execution. ## What changed - Added Bandit to pre-commit backend checks. - Integrated eslint-plugin-security into the existing frontend ESLint setup used by pre-commit. - Added dedicated audit tasks: - backend audit via pip-audit - frontend audit via yarn npm audit - Updated CI/CD workflow to include and gate on frontend/backend audit jobs. - Switched backend vulnerability scanning from Safety to pip-audit to avoid interactive/auth requirements in CI. - Updated backend dependency set and lockfile to resolve test dependency conflicts and keep the environment solvable. - Marked backend integration API tests with the integration marker so marker-based unit/integration separation works consistently. ## Validation - Pre-commit hooks run and pass after formatting/autofixes. - Branch commit created successfully after hook-driven file updates. - Branch pushed to remote and tracking is configured. ## Notes - pip-audit now executes from backend context (for example via uv --directory backend run ...), matching project layout. - Remaining reported vulnerabilities depend on upstream package fix availability/constraints and may require follow-up once publishable fix versions are consumable. ## Follow-ups (optional) - Add a curated pip-audit ignore policy for non-actionable/transient advisories with rationale. - Open a focused follow-up PR for remaining dependency advisories once upstream fixes are practically installable. Co-authored-by: copilotcoder <copilotcoder@darkhelm.org> Reviewed-on: https://dogar.darkhelm.org/DarkHelm.org/plex-playlist/pulls/74
2026-07-13 22:19:57 -04:00
},
{
"description": "Skip automatic updates for project Python runtime constraint",
"matchManagers": ["pep621"],
"matchPackageNames": ["python"],
"enabled": false
}
],
Stabilize self-hosted CI workflows and resolve issue #62 (#73) ## Summary Hardens CI workflows for self-hosted Gitea runners by stabilizing E2E execution and Renovate behavior across internal/external network paths. Closes #62 ## What Changed ### E2E workflow reliability - Fixed E2E workspace handoff to ensure expected repository contents are present during test execution. - Added stricter preflight checks for required frontend files before running E2E. - Reduced mount/path fragility while preserving runtime image pull and compose flow. ### Renovate workflow hardening - Added internal-first endpoint reachability selection with fallback handling. - Added token preflight checks for repository access. - Added explicit host-rule auth handling for API/git paths. - Added container-level connectivity preflight diagnostics. - Added git URL override aligned with selected endpoint context. - Removed incorrect forced Dogar host-IP pinning that broke HTTPS clone routing. ## Why CI behavior was sensitive to runner networking and Renovate clone/auth interactions. These changes make the workflow deterministic in our runner topology and address recurring CI failures. ## Scope - Workflow logic only (`cicd.yaml`, `renovate.yml`) - No app feature or API behavior changes ## Validation - Workflow YAML validation passed during updates. - Changes were applied and verified iteratively from real failing run diagnostics. Co-authored-by: copilotcoder <copilotcoder@darkhelm.org> Reviewed-on: https://dogar.darkhelm.org/DarkHelm.org/plex-playlist/pulls/73
2026-07-13 11:16:16 -04:00
"osvVulnerabilityAlerts": false,
"vulnerabilityAlerts": {
"enabled": true,
"schedule": ["at any time"]
},
"labels": ["dependencies"],
"commitMessagePrefix": "chore:",
"commitMessageTopic": "{{depName}}",
"commitMessageExtra": "to {{newVersion}}",
"commitMessageSuffix": "",
"prBodyTemplate": "This PR contains the following updates:\n\n| Package | Change | Age | Adoption | Passing | Confidence |\n|---|---|---|---|---|---|\n{{#each upgrades}}\n|{{depName}}|{{#if displayFrom}}`{{{displayFrom}}}` -> `{{{displayTo}}}`{{else}}`{{{newVersion}}}`{{/if}}|[![age](https://badges.renovateapi.com/packages/{{datasource}}/{{depName}}/{{newVersion}}/age-slim)](https://docs.renovatebot.com/merge-confidence/)|[![adoption](https://badges.renovateapi.com/packages/{{datasource}}/{{depName}}/{{newVersion}}/adoption-slim)](https://docs.renovatebot.com/merge-confidence/)|[![passing](https://badges.renovateapi.com/packages/{{datasource}}/{{depName}}/{{newVersion}}/compatibility-slim/{{currentVersion}})](https://docs.renovatebot.com/merge-confidence/)|[![confidence](https://badges.renovateapi.com/packages/{{datasource}}/{{depName}}/{{newVersion}}/confidence-slim/{{currentVersion}})](https://docs.renovatebot.com/merge-confidence/)|\n{{/each}}\n\n---\n\n### Release Notes\n\n{{#each upgrades}}\n{{#if hasReleaseNotes}}\n<details>\n<summary>{{depName}}</summary>\n\n{{#each releases}}\n#### {{title}}\n\n{{#if body}}\n{{body}}\n{{/if}}\n{{/each}}\n\n</details>\n{{/if}}\n{{/each}}\n\n### Configuration\n\n📅 **Schedule**: {{schedule}}\n\n🚦 **Automerge**: {{#if isAutomerge}}Enabled{{else}}Disabled{{/if}}\n\n♻ **Rebasing**: {{#if isRebasing}}Rebasing{{else}}Not rebasing{{/if}}\n\n👥 **Reviewers**: {{#if reviewers}}{{reviewers}}{{else}}None{{/if}}\n\n---\n\n*This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).*"
}