Repository navigation
Expand file tree
/
Copy pathdefault.json
More file actions
131 lines (131 loc) · 4.6 KB
/
Copy pathdefault.json
File metadata and controls
131 lines (131 loc) · 4.6 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
{
"extends": [
"config:recommended",
":semanticCommits"
],
"timezone": "Europe/Zurich",
"branchPrefix": "renovate-",
"osvVulnerabilityAlerts": true,
"hostRules": [
{
"matchHost": "registry.npmjs.org",
"token": "{{ secrets.HELIX_NPM_TOKEN }}",
"hostType": "npm"
}
],
"packageRules": [
{
"matchPackageNames": ["@adobe/fetch"],
"rangeStrategy": "replace"
},
{
"matchPackageNames": ["^@adobe/helix-shared-.*"],
"rangeStrategy": "replace"
},
{
"matchPackageNames": ["eslint"],
"allowedVersions": "<10.0.0"
},
{
"matchPackageNames": ["quick-lru"],
"allowedVersions": "<6.0.0"
},
{
"matchPackageNames": ["callsites"],
"allowedVersions": "<4.0.0"
},
{
"matchPackageNames": ["escape-string-regexp"],
"allowedVersions": "<5.0.0"
},
{
"matchPackageNames": ["p-limit"],
"allowedVersions": "<4.0.0"
},
{
"matchPackageNames": ["cimg/node"],
"allowedVersions": "<19"
},
{
"matchPackageNames": ["@aws-sdk/client-s3"],
"allowedVersions": "!/3\\.29\\.0/"
},
{
"matchPackageNames": ["@adobe/helix-cli"],
"allowedVersions": "<14"
},
{
"groupName": "adobe fixes",
"matchUpdateTypes": ["patch", "pin", "digest", "minor"],
"automerge": true,
"matchPackagePatterns": ["^@adobe/"],
"schedule": ["at any time"]
},
{
"groupName": "adobe major",
"matchUpdateTypes": ["major"],
"matchPackagePatterns": ["^@adobe/"],
"automerge": false,
"schedule": ["at any time"]
},
{
"groupName": "external fixes",
"matchUpdateTypes": ["patch", "pin", "digest", "minor"],
"automerge": true,
"schedule": [
"after 2pm on Monday"
],
"matchPackagePatterns": ["^.+"],
"excludePackagePatterns": ["^@adobe/"],
"minimumReleaseAge": "14 days"
},
{
"groupName": "external major",
"matchUpdateTypes": ["major"],
"automerge": false,
"matchPackagePatterns": ["^.+"],
"excludePackagePatterns": ["^@adobe/"],
"schedule": ["after 2pm on Monday"],
"minimumReleaseAge": "14 days"
},
{
"description": "Split dev dependencies out of the two external groups above, so each group is smaller. The `renovate/stability-days` check is computed per branch, so any single member still inside its minimum release age holds the whole group back; smaller groups reach a fully-aged state more often. Split by depType rather than by package name so it needs no maintenance as dependencies change. These rules come after the two catch-all rules above and therefore override their `groupName`; the catch-alls deliberately keep no `matchDepTypes`, so anything that is not a devDependency -- runtime, optional and peer deps, npm `engines`, and every non-npm manager such as github-actions or dockerfile -- keeps its grouping and its 14-day minimum release age.",
"groupName": "external dev fixes",
"matchDepTypes": ["devDependencies"],
"matchUpdateTypes": ["patch", "pin", "digest", "minor"],
"matchPackagePatterns": ["^.+"],
"excludePackagePatterns": ["^@adobe/"]
},
{
"description": "Same dev/runtime split as above, for major updates.",
"groupName": "external dev major",
"matchDepTypes": ["devDependencies"],
"matchUpdateTypes": ["major"],
"matchPackagePatterns": ["^.+"],
"excludePackagePatterns": ["^@adobe/"]
},
{
"description": "Renovate cannot enforce a minimum release age on these update types, because they carry no usable release timestamp. Leaving them subject to `minimumReleaseAge` makes the branch-level `renovate/stability-days` check go permanently yellow, which silently blocks automerge forever. Mirrors the carve-outs in Renovate's own `security:minimumReleaseAge*` presets.",
"matchUpdateTypes": [
"pin",
"pinDigest",
"bump",
"lockfileUpdate",
"lockFileMaintenance",
"rollback",
"replacement"
],
"minimumReleaseAge": null
},
{
"description": "Digest updates do have a release timestamp at lookup time, but the branch stage does not always carry it forward (renovatebot/renovate#45236), which strands the stability check in a permanently pending state. Accept a timestamp when one is available instead of requiring it.",
"matchUpdateTypes": ["digest"],
"minimumReleaseAgeBehaviour": "timestamp-optional"
},
{
"matchDatasources": ["orb"],
"matchUpdateTypes": ["patch", "minor"],
"automerge": true
}
]
}