Skip to content

Commit

Permalink
Renovate should pin dependencies
Browse files Browse the repository at this point in the history
Signed-off-by: John Strunk <[email protected]>
  • Loading branch information
JohnStrunk committed May 21, 2024
1 parent 59d8133 commit d51c006
Showing 1 changed file with 21 additions and 11 deletions.
32 changes: 21 additions & 11 deletions .github/renovate.json5
Original file line number Diff line number Diff line change
@@ -1,15 +1,15 @@
{
// JSON5 spec: https://json5.org/
// Renovate docs: https://docs.renovatebot.com/configuration-options/

"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": [
"config:recommended", // Use recommended settings
"docker:pinDigests", // Pin container digests
"config:recommended", // Use recommended settings
"docker:pinDigests", // Pin container digests
"helpers:pinGitHubActionDigests", // Pin GitHub action digests
":enablePreCommit", // Enable updates to pre-commit repos
":gitSignOff", // Add Signed-off-by line to commit messages
":pinDevDependencies" // Pin dev dependencies also
":enablePreCommit", // Enable updates to pre-commit repos
":gitSignOff", // Add Signed-off-by line to commit messages
":pinDependencies", // Pin dependencies
":pinDevDependencies" // Pin dev dependencies also
],
// Files to ignore
"ignorePaths": [
Expand All @@ -18,17 +18,27 @@
"labels": [
"dependencies"
],
"lockFileMaintenance": {"enabled": true},
"lockFileMaintenance": {
"enabled": true
},
"packageRules": [
{
"description": "Update renovatebot/pre-commit-hooks weekly to decrease noise",
"matchPackageNames": ["renovatebot/pre-commit-hooks"],
"schedule": ["before 9am on monday"]
"matchPackageNames": [
"renovatebot/pre-commit-hooks"
],
"schedule": [
"before 9am on monday"
]
},
{
"description": "Devcontainer 'features' don't support digest pinning",
"matchManagers": ["devcontainer"],
"matchDepTypes": ["feature"],
"matchManagers": [
"devcontainer"
],
"matchDepTypes": [
"feature"
],
"pinDigests": false
}
],
Expand Down

0 comments on commit d51c006

Please sign in to comment.