You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
renovate-presets/fleet.json:4-40 groups minor/patch updates but leaves digest updates outside the GitHub Actions group and does not define a schedule, commit rate, branch limit, PR limit, release age, PR-creation gate, or major-update approval. In the 2026-06-14..2026-08-01 audit window, 460 of 974 retrievable Renovate PRs were digest updates; grouped non-major work merged 174/180 while frequent digest families produced much more discarded work. This is a current intake-control gap, not evidence that routine Renovate grouping should be removed.
Scope
Add a bounded weekly maintenance window and fleet branch/PR budgets.
Group trusted GitHub Actions digest/pin/minor/patch updates together.
Delay routine PR creation until branch checks are not pending and releases have aged.
Route majors through the Dependency Dashboard while security updates bypass routine cadence.
Non-Goals
Do not revert to Dependabot or disable platform auto-merge for clean routine updates.
Do not delay vulnerability-alert/security updates behind the weekly window.
Do not include the nine Workflows-owned dev-tool pins disabled at fleet.json:11-15.
Scaffold-only completion does NOT count: adding undocumented keys without schema validation and a representative dry-run is not completion.
Tasks
Update renovate-presets/fleet.json with a documented weekly 4-hour schedule, commitHourlyLimit, prConcurrentLimit, and branchConcurrentLimit set to conservative fleet values.
Extend the GitHub Actions package rule at renovate-presets/fleet.json:29-35 to group digest, pin, minor, and patch updates for trusted actions.
Add routine-update minimumReleaseAge and prCreation policy without applying those delays to vulnerability alerts.
Add a major-update rule using dependencyDashboardApproval while preserving visible, actively handled majors.
Define grouped lock-file maintenance cadence explicitly instead of inheriting an always-available default.
Add tests/workflows/test_renovate_fleet_policy.py to parse the real preset and assert the schedule, limits, security bypass, digest grouping, dev-tool exclusions, and major lane.
Update docs/ci/TOOL_VERSION_MANAGEMENT.md, docs/WORKFLOW_GUIDE.md, and renovate-presets/README.md with the intake budget and emergency/security path.
Add the Renovate config validator command to scripts/dev_check.sh or the existing dependency-policy validation job.
Renovate config validation accepts renovate.json, renovate-presets/fleet.json, and any inherited generated preset.
A representative Renovate dry-run for Workflows and one consumer reports at most three concurrent routine branches and groups trusted GitHub Actions digest updates into one branch.
The dry-run evidence shows a routine non-security release is held by the maintenance/release-age policy while a vulnerability-alert update is not held.
Deliberate-break gate: temporarily remove digest from the GitHub Actions group; tests/workflows/test_renovate_fleet_policy.py::test_trusted_action_digests_are_grouped must fail. Restore the rule before review.
Implementation Notes
Current preset: renovate-presets/fleet.json; Workflows override: renovate.json; consumer entrypoint: templates/consumer-repo/.github/renovate.json.
Related tests/docs: tests/workflows/test_dependency_bot_conditions.py, tests/workflows/test_consumer_sync_create_only_evidence.py, docs/ci/TOOL_VERSION_MANAGEMENT.md, docs/WORKFLOW_GUIDE.md, docs/ops/CONSUMER_REPO_MAINTENANCE.md, and scripts/dev_check.sh.
Start with commitHourlyLimit: 1 or 2, prConcurrentLimit: 3, and branchConcurrentLimit: 3; change these only with dry-run evidence.
Preserve native automerge for the green routine lane and a no-delay security path.
Why
renovate-presets/fleet.json:4-40groups minor/patch updates but leaves digest updates outside the GitHub Actions group and does not define a schedule, commit rate, branch limit, PR limit, release age, PR-creation gate, or major-update approval. In the 2026-06-14..2026-08-01 audit window, 460 of 974 retrievable Renovate PRs were digest updates; grouped non-major work merged 174/180 while frequent digest families produced much more discarded work. This is a current intake-control gap, not evidence that routine Renovate grouping should be removed.Scope
Non-Goals
fleet.json:11-15.Tasks
renovate-presets/fleet.jsonwith a documented weekly 4-hour schedule,commitHourlyLimit,prConcurrentLimit, andbranchConcurrentLimitset to conservative fleet values.renovate-presets/fleet.json:29-35to groupdigest,pin,minor, andpatchupdates for trusted actions.minimumReleaseAgeandprCreationpolicy without applying those delays to vulnerability alerts.dependencyDashboardApprovalwhile preserving visible, actively handled majors.tests/workflows/test_renovate_fleet_policy.pyto parse the real preset and assert the schedule, limits, security bypass, digest grouping, dev-tool exclusions, and major lane.docs/ci/TOOL_VERSION_MANAGEMENT.md,docs/WORKFLOW_GUIDE.md, andrenovate-presets/README.mdwith the intake budget and emergency/security path.scripts/dev_check.shor the existing dependency-policy validation job.Acceptance Criteria
python -m pytest tests/workflows/test_renovate_fleet_policy.py tests/workflows/test_dependency_bot_conditions.py -qpasses.renovate.json,renovate-presets/fleet.json, and any inherited generated preset.digestfrom the GitHub Actions group;tests/workflows/test_renovate_fleet_policy.py::test_trusted_action_digests_are_groupedmust fail. Restore the rule before review.Implementation Notes
renovate-presets/fleet.json; Workflows override:renovate.json; consumer entrypoint:templates/consumer-repo/.github/renovate.json.tests/workflows/test_dependency_bot_conditions.py,tests/workflows/test_consumer_sync_create_only_evidence.py,docs/ci/TOOL_VERSION_MANAGEMENT.md,docs/WORKFLOW_GUIDE.md,docs/ops/CONSUMER_REPO_MAINTENANCE.md, andscripts/dev_check.sh.commitHourlyLimit: 1or2,prConcurrentLimit: 3, andbranchConcurrentLimit: 3; change these only with dry-run evidence.