Skip to content

chore: configure Renovate to pin GitHub Action digests - #11

Merged
deviantintegral merged 4 commits into
mainfrom
copilot/configure-renovate-python-version
Feb 25, 2026
Merged

deviantintegral merged 4 commits into
mainfrom
copilot/configure-renovate-python-version

Conversation

Copilot AI commented Feb 25, 2026 •

Copy link
Copy Markdown
Contributor

Add helpers:pinGitHubActionDigests preset to pin GitHub Action references to immutable SHA digests for supply-chain security.

{
  "extends": [
    "config:recommended",
    "helpers:pinGitHubActionDigests"
  ]
}

The Python version constraint (allowedVersions: "<3.14") was initially added but removed since Renovate doesn't support dynamically trailing N minor versions behind. A static constraint would require manual config updates each Python release. Instead, unwanted Python upgrade PRs can simply be closed.


✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

Copilot AI and others added 2 commits February 25, 2026 21:47
Co-authored-by: deviantintegral <255023+deviantintegral@users.noreply.github.com>
Co-authored-by: deviantintegral <255023+deviantintegral@users.noreply.github.com>
Copilot AI changed the title [WIP] Configure Renovate to pin GitHub Action hashes and set Python version Configure Renovate to pin GitHub Action digests and constrain Python version Feb 25, 2026
@deviantintegral

Copy link
Copy Markdown
Owner

@copilot I don't like how this requires manual updates for python in the renovate config. Is there a better way to do this? Or should we just remove the package rule and rely on closing pull requests?

Renovate doesn't support trailing N versions behind dynamically,
so a static allowedVersions requires manual updates each release.
Relying on closing unwanted PRs is simpler and maintenance-free.

Co-authored-by: deviantintegral <255023+deviantintegral@users.noreply.github.com>

Copilot AI commented Feb 25, 2026

Copy link
Copy Markdown
Contributor Author

@copilot I don't like how this requires manual updates for python in the renovate config. Is there a better way to do this? Or should we just remove the package rule and rely on closing pull requests?

Renovate doesn't have a native "trail N minor versions behind" feature, so allowedVersions: "<3.14" would need manual bumps every Python release. Removed the package rule in 8b1ab9c — closing unwanted PRs is simpler and maintenance-free.

Copilot AI changed the title Configure Renovate to pin GitHub Action digests and constrain Python version Configure Renovate to pin GitHub Action digests Feb 25, 2026
@deviantintegral deviantintegral changed the title Configure Renovate to pin GitHub Action digests chore: configure Renovate to pin GitHub Action digests Feb 25, 2026
@deviantintegral
deviantintegral marked this pull request as ready for review February 25, 2026 21:59
@deviantintegral
deviantintegral merged commit 23c8242 into main Feb 25, 2026
2 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants