Skip to content

chore: tune renovate update grouping#325

Merged
choufraise merged 1 commit into
mainfrom
chore/renovate-grouping
Jun 8, 2026
Merged

chore: tune renovate update grouping#325
choufraise merged 1 commit into
mainfrom
chore/renovate-grouping

Conversation

@choufraise

Copy link
Copy Markdown
Collaborator

Summary

  • group routine minor updates for Go, www, GitHub Actions, Helm, Mise, .tool-versions, and tracked image versions into one weekly PR
  • disable routine patch updates and lock-file maintenance PRs
  • keep major updates behind Dependency Dashboard approval
  • enable security-only patch PRs through vulnerability alerts and OSV

Reasoning

NAuth is not auto-deployed from dependency PRs. Dependency updates only take effect when NAuth is released, so weekly patch-level churn adds review noise without immediate runtime value.

Reduce weekly Renovate PR noise for NAuth, since dependency updates do not affect any running deployment until the project is released.

Group routine minor updates across Go, www, GitHub Actions, Helm, Mise, .tool-versions, and tracked container image versions into one weekly PR.

Disable routine patch updates and lock-file maintenance PRs. Patch updates should only be raised when they fix a known vulnerability.

Keep major updates visible in the Dependency Dashboard and require manual approval before Renovate opens PRs for them.

Enable vulnerability-driven security PRs through GitHub vulnerability alerts and OSV, labelled as security updates.

Signed-off-by: Thobias Karlsson <thobias.karlsson@gmail.com>
@choufraise choufraise requested a review from a team as a code owner June 8, 2026 10:50
@choufraise choufraise self-assigned this Jun 8, 2026
@choufraise choufraise added the type: maintenance Cleanup, refactoring, dependency updates and other maintenance label Jun 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type: maintenance Cleanup, refactoring, dependency updates and other maintenance

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants