Skip to content

chore: Configure Renovate - #3086

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/configure
Open

renovate[bot] wants to merge 1 commit into
masterfrom
renovate/configure

Conversation

@renovate

@renovate renovate Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Welcome to Renovate! This is an onboarding PR to help you understand and configure settings before regular Pull Requests begin.

🚦 To activate Renovate, merge this Pull Request. To disable Renovate, simply close this Pull Request unmerged.

📚 See our Reading List for relevant documentation you may be interested in reading.

🔡 Do you want to change how Renovate upgrades your dependencies? Add your custom config to renovate.json in this branch. Renovate will update the Pull Request description the next time it runs.


Detected Package Files

  • Cargo.toml (cargo)
  • crates/tracedecay-agent-hosts/Cargo.toml (cargo)
  • crates/tracedecay-api/Cargo.toml (cargo)
  • crates/tracedecay-application/Cargo.toml (cargo)
  • crates/tracedecay-automation-runtime/Cargo.toml (cargo)
  • crates/tracedecay-automation/Cargo.toml (cargo)
  • crates/tracedecay-capture/Cargo.toml (cargo)
  • crates/tracedecay-cli/Cargo.toml (cargo)
  • crates/tracedecay-code-extraction/Cargo.toml (cargo)
  • crates/tracedecay-code-index-retention/Cargo.toml (cargo)
  • crates/tracedecay-code-index-runtime/Cargo.toml (cargo)
  • crates/tracedecay-code-index/Cargo.toml (cargo)
  • crates/tracedecay-configuration/Cargo.toml (cargo)
  • crates/tracedecay-contracts/Cargo.toml (cargo)
  • crates/tracedecay-daemon-control/Cargo.toml (cargo)
  • crates/tracedecay-daemon-identity/Cargo.toml (cargo)
  • crates/tracedecay-daemon-protocol/Cargo.toml (cargo)
  • crates/tracedecay-daemon-service/Cargo.toml (cargo)
  • crates/tracedecay-dashboard-api/Cargo.toml (cargo)
  • crates/tracedecay-domain/Cargo.toml (cargo)
  • crates/tracedecay-framing/Cargo.toml (cargo)
  • crates/tracedecay-global-db/Cargo.toml (cargo)
  • crates/tracedecay-graph-db/Cargo.toml (cargo)
  • crates/tracedecay-graph-query/Cargo.toml (cargo)
  • crates/tracedecay-hooks/Cargo.toml (cargo)
  • crates/tracedecay-host-admission/Cargo.toml (cargo)
  • crates/tracedecay-host-integration/Cargo.toml (cargo)
  • crates/tracedecay-lcm/Cargo.toml (cargo)
  • crates/tracedecay-lsp/Cargo.toml (cargo)
  • crates/tracedecay-maintenance/Cargo.toml (cargo)
  • crates/tracedecay-mcp-catalog/Cargo.toml (cargo)
  • crates/tracedecay-mcp/Cargo.toml (cargo)
  • crates/tracedecay-policy/Cargo.toml (cargo)
  • crates/tracedecay-privacy/Cargo.toml (cargo)
  • crates/tracedecay-private-fs/Cargo.toml (cargo)
  • crates/tracedecay-project/Cargo.toml (cargo)
  • crates/tracedecay-query/Cargo.toml (cargo)
  • crates/tracedecay-runtime-core/Cargo.toml (cargo)
  • crates/tracedecay-rusqlite-runtime/Cargo.toml (cargo)
  • crates/tracedecay-sdk/Cargo.toml (cargo)
  • crates/tracedecay-search-eval/Cargo.toml (cargo)
  • crates/tracedecay-session-memory/Cargo.toml (cargo)
  • crates/tracedecay-session-runtime/Cargo.toml (cargo)
  • crates/tracedecay-session-temporal-store/Cargo.toml (cargo)
  • crates/tracedecay-sessions/Cargo.toml (cargo)
  • crates/tracedecay-source-edit/Cargo.toml (cargo)
  • crates/tracedecay-store-runtime/Cargo.toml (cargo)
  • crates/tracedecay-store/Cargo.toml (cargo)
  • crates/tracedecay-temporal-query/Cargo.toml (cargo)
  • crates/tracedecay-tool-catalog/Cargo.toml (cargo)
  • crates/tracedecay/Cargo.toml (cargo)
  • sdks/codegen/Cargo.toml (cargo)
  • .github/hauler/Dockerfile (dockerfile)
  • .github/actions/setup-linux-mold/action.yml (github-actions)
  • .github/actions/setup-pnpm/action.yml (github-actions)
  • .github/workflows/ci.yml (github-actions)
  • .github/workflows/distribution-acceptance.yml (github-actions)
  • .github/workflows/hauler-ci.yml (github-actions)
  • .github/workflows/hauler-image.yml (github-actions)
  • .github/workflows/hawk.yml (github-actions)
  • .github/workflows/plugin-validation.yml (github-actions)
  • .github/workflows/pr-run-cleanup.yml (github-actions)
  • .github/workflows/release-beta.yml (github-actions)
  • .github/workflows/release-please.yml (github-actions)
  • .github/workflows/release-pr-integrity.yml (github-actions)
  • .github/workflows/release.yml (github-actions)
  • .github/workflows/sdk-conformance.yml (github-actions)
  • crates/tracedecay-code-extraction/fixtures/cross-file-calls/go/go.mod (gomod)
  • crates/tracedecay-code-extraction/fixtures/go-satisfaction/go.mod (gomod)
  • crates/tracedecay-code-extraction/fixtures/typescript-monorepo/package.json (npm)
  • crates/tracedecay-code-extraction/fixtures/typescript-monorepo/packages/shared/package.json (npm)
  • dashboard/package.json (npm)
  • mockups/ui-concept-v2/app/package.json (npm)
  • package.json (npm)
  • plugin/chatgpt-extension/package.json (npm)
  • plugin/cursor-native-extension/package.json (npm)
  • plugin/pi/package.json (npm)
  • pnpm-workspace.yaml (npm)
  • sdks/typescript/package.json (npm)
  • rust-toolchain.toml (rust-toolchain)

Configuration Summary

Based on the default config's presets, Renovate will:

  • Start dependency updates only once this onboarding PR is merged
  • Hopefully safe environment variables to allow users to configure.
  • Show all Merge Confidence badges for pull requests.
  • Enable Renovate Dependency Dashboard creation.
  • Use semantic commit type fix for dependencies and chore for all others if semantic commits are in use.
  • Ignore node_modules, bower_components, vendor and various test/tests (except for nuget) directories.
  • Group known monorepo packages together.
  • Use curated list of recommended non-monorepo package groupings.
  • Show only the Age and Confidence Merge Confidence badges for pull requests.
  • Apply crowd-sourced package replacement rules.
  • Apply crowd-sourced workarounds for known problems with packages.
  • Ensure that every dependency pinned by digest and sourced from Forgejo contains a link to the commit-to-commit diff
  • Ensure that every dependency pinned by digest and sourced from Gitea contains a link to the commit-to-commit diff
  • Ensure that every dependency pinned by digest and sourced from GitHub.com and Github enterprise contains a link to the commit-to-commit diff
  • Ensure that every dependency pinned by digest and sourced from GitLab.com contains a link to the commit-to-commit diff
  • Correctly link to the source code for golang.org/x packages
  • Link to pkg.go.dev/... for golang.org/x packages' title
  • Provide a link to octochangelog's improved breakdown for Renovate's changelogs

What to Expect

With your current configuration, Renovate will create 10 Pull Requests, up to a maximum of 47 over time (see docs for prConcurrentLimit):

chore(deps): update actions/attest digest to 1e69f48
  • Schedule: ["at any time"]
  • Branch name: renovate/actions-attest-digest
  • Merge into: master
  • Upgrade actions/attest to 1e69f48acb82d1966a394da916b4c1698aa569d6
chore(deps): update dtolnay/rust-toolchain digest to 89b1218
  • Schedule: ["at any time"]
  • Branch name: renovate/dtolnay-rust-toolchain-digest
  • Merge into: master
  • Upgrade dtolnay/rust-toolchain to 89b12181fb390509a0842a86cc55eeb8eb928c1d
chore(deps): update rui314/setup-mold digest to 10ca16b
  • Schedule: ["at any time"]
  • Branch name: renovate/rui314-setup-mold-digest
  • Merge into: master
  • Upgrade rui314/setup-mold to 10ca16bf91dc22e05ebdc935cad9c75ea248f621
chore(deps): update taiki-e/install-action digest to c6be25d
  • Schedule: ["at any time"]
  • Branch name: renovate/taiki-e-install-action-digest
  • Merge into: master
  • Upgrade taiki-e/install-action to c6be25d576b61102b3af9c1f35a7f2b3a55b5e3a
chore(deps): update dependency @​commitlint/cli to v21.2.3
  • Schedule: ["at any time"]
  • Branch name: renovate/commitlint-monorepo
  • Merge into: master
  • Upgrade @commitlint/cli to 21.2.3
chore(deps): update dependency @radix-ui/react-dialog to v1.1.23
  • Schedule: ["at any time"]
  • Branch name: renovate/radix-ui-primitives-monorepo
  • Merge into: master
  • Upgrade @radix-ui/react-dialog to 1.1.23
chore(deps): update dependency @​tanstack/react-virtual to v3.14.13
  • Schedule: ["at any time"]
  • Branch name: renovate/tanstack-virtual-monorepo
  • Merge into: master
  • Upgrade @tanstack/react-virtual to 3.14.13
chore(deps): update dependency @​types/node to v22.20.5
  • Schedule: ["at any time"]
  • Branch name: renovate/node-22.x-lockfile
  • Merge into: master
  • Upgrade @types/node to 22.20.5
chore(deps): update dependency 3d-force-graph to v1.80.1
  • Schedule: ["at any time"]
  • Branch name: renovate/3d-force-graph-1.x-lockfile
  • Merge into: master
  • Upgrade 3d-force-graph to 1.80.1
chore(deps): update dependency node to v22.23.3
  • Schedule: ["at any time"]
  • Branch name: renovate/node-22.x
  • Merge into: master
  • Upgrade node to 22.23.3
chore(deps): update dependency react-router to v7.18.4
  • Schedule: ["at any time"]
  • Branch name: renovate/react-router-monorepo
  • Merge into: master
  • Upgrade react-router to 7.18.4
chore(deps): update dependency tsx to v4.23.15
  • Schedule: ["at any time"]
  • Branch name: renovate/tsx-4.x-lockfile
  • Merge into: master
  • Upgrade tsx to 4.23.15
chore(deps): update dependency vitest to v4.1.11
  • Schedule: ["at any time"]
  • Branch name: renovate/vitest-monorepo
  • Merge into: master
  • Upgrade vitest to 4.1.11
chore(deps): update dependency vscode-languageclient to v10.1.2
  • Schedule: ["at any time"]
  • Branch name: renovate/vscode-languageclient-10.x-lockfile
  • Merge into: master
  • Upgrade vscode-languageclient to 10.1.2
chore(deps): update dependency zustand to v5.0.15
  • Schedule: ["at any time"]
  • Branch name: renovate/zustand-5.x-lockfile
  • Merge into: master
  • Upgrade zustand to 5.0.15
chore(deps): update testing-library monorepo
chore(deps): update astral-sh/setup-uv action to v8.3.2
  • Schedule: ["at any time"]
  • Branch name: renovate/astral-sh-setup-uv-8.x
  • Merge into: master
  • Upgrade astral-sh/setup-uv to 11f9893b081a58869d3b5fccaea48c9e9e46f990
chore(deps): update dependency @​modelcontextprotocol/sdk to v1.32.0
  • Schedule: ["at any time"]
  • Branch name: renovate/modelcontextprotocol-sdk-1.x-lockfile
  • Merge into: master
  • Upgrade @modelcontextprotocol/sdk to 1.32.0
chore(deps): update dependency @​tanstack/react-query to v5.104.1
  • Schedule: ["at any time"]
  • Branch name: renovate/tanstack-query-monorepo
  • Merge into: master
  • Upgrade @tanstack/react-query to 5.104.1
chore(deps): update dependency @​types/node to v26.6.4
  • Schedule: ["at any time"]
  • Branch name: renovate/node-26.x-lockfile
  • Merge into: master
  • Upgrade @types/node to 26.6.4
chore(deps): update dependency @​types/vscode to v1.140.0
  • Schedule: ["at any time"]
  • Branch name: renovate/vscode-1.x-lockfile
  • Merge into: master
  • Upgrade @types/vscode to 1.140.0
chore(deps): update dependency python to v3.14.8
  • Schedule: ["at any time"]
  • Branch name: renovate/python-3.x
  • Merge into: master
  • Upgrade python to 3.14.8
  • Upgrade python to 3.14
chore(deps): update dependency zod to v4.6.5
  • Schedule: ["at any time"]
  • Branch name: renovate/zod-4.x-lockfile
  • Merge into: master
  • Upgrade zod to 4.6.5
chore(deps): update playwright monorepo to v1.63.0
  • Schedule: ["at any time"]
  • Branch name: renovate/playwright-monorepo
  • Merge into: master
  • Upgrade @playwright/test to sha512-oxMK4vllB9RK5NQ2l1pq1IfOf2AvnEuj/vYGDj0H2nMtmtZpKtCwt/l00GEO6xjGfpBNAvjovvYdCm50dRQkpQ==
  • Upgrade playwright to 1.63.0
  • Upgrade playwright-core to 1.63.0
chore(deps): update pnpm to v12.9.1
  • Schedule: ["at any time"]
  • Branch name: renovate/pnpm-12.x
  • Merge into: master
  • Upgrade pnpm to sha512-BrBV//XNINwSeB3hc87TMQzglRvy7GICEaFgRdVETVyTpmMhB2TvKaZTphBFm6A2jw50+E2AxUcjz5Wq57wNbQ==
chore(deps): update react monorepo to v19.3.0
chore(deps): update rust to v1.99.0
  • Schedule: ["at any time"]
  • Branch name: renovate/rust-1.x
  • Merge into: master
  • Upgrade rust to 1.99.0
fix(deps): update dependency lucide-react to ^0.577.0
  • Schedule: ["at any time"]
  • Branch name: renovate/lucide-monorepo
  • Merge into: master
  • Upgrade lucide-react to sha512-4LjoFv2eEPwYDPg/CUdBJQSDfPyzXCRrVW1X7jrx/trgxnxkHFjnVZINbzvzxjN70dxychOfg+FTYwBiS3pQ5A==
fix(deps): update dependency three to ^0.186.0
  • Schedule: ["at any time"]
  • Branch name: renovate/three-0.x
  • Merge into: master
  • Upgrade three to sha512-blFeqb49wRCSGUGj7gtpfnSGHy2lwDk94RhUmS1c/hTby70kvChbWpkJ4Pm1390LqzzvTmzgXKHPEafJwCb8jA==
  • Upgrade @types/three to sha512-mxYSBpDC+D0pLfSP6sW4WZTcT+nrtmZcimMqnVmy36Hte3XpeYSrvgg4TRdaM1GemGog1AWzI5qL2VoIfMXbJQ==
chore(deps): update actions/setup-node action to v7
  • Schedule: ["at any time"]
  • Branch name: renovate/actions-setup-node-7.x
  • Merge into: master
  • Upgrade actions/setup-node to 820762786026740c76f36085b0efc47a31fe5020
chore(deps): update actions/setup-python action to v7
  • Schedule: ["at any time"]
  • Branch name: renovate/actions-setup-python-7.x
  • Merge into: master
  • Upgrade actions/setup-python to 5fda3b95a4ea91299a34e894583c3862153e4b97
chore(deps): update astral-sh/setup-uv action to v10
  • Schedule: ["at any time"]
  • Branch name: renovate/astral-sh-setup-uv-10.x
  • Merge into: master
  • Upgrade astral-sh/setup-uv to c18668ad3cf93ea998bef934396af7bb5c839dc7
chore(deps): update dependency @​rsbuild/core to v2
  • Schedule: ["at any time"]
  • Branch name: renovate/rsbuild-core-2.x
  • Merge into: master
  • Upgrade @rsbuild/core to sha512-avPW0j6RaEbtV2mfl0AzTAJEimPX4Xj0pCcZyxNCrE9vkS91HmweM5V7XQj3kI5iTYfHRp9Y6To8RRHYLEvG7A==
chore(deps): update dependency @​rsbuild/plugin-react to v2
  • Schedule: ["at any time"]
  • Branch name: renovate/rsbuild-plugin-react-2.x
  • Merge into: master
  • Upgrade @rsbuild/plugin-react to sha512-tLtUedsRtTLS6M4VtwzI6aakFLOFdgl9Sh1ZNBWvxb0Te3EnHrppaE7UiYEmDUXQDJ50gfr6yyirtxY5N6moyg==
chore(deps): update dependency @​rslib/core to v1
  • Schedule: ["at any time"]
  • Branch name: renovate/rslib-core-1.x
  • Merge into: master
  • Upgrade @rslib/core to sha512-a5IZiyf9sNeeE9jcTsTmz16vxcThpbOSJg0BZXzJAxrUFOZX5xG25PJua9hr0LDWGryBX2UQTruVsLQ8BCpqng==
chore(deps): update dependency jsdom to v30
  • Schedule: ["at any time"]
  • Branch name: renovate/jsdom-30.x
  • Merge into: master
  • Upgrade jsdom to sha512-0FFE/jE1rppmVfUrJUgxqXjcwolZYIGtAgj1pTussMhNZxIxi7W/PvfWaMNroGi2B36X1IKHbexpZ9DhkoOPiQ==
chore(deps): update dependency macos to v26
  • Schedule: ["at any time"]
  • Branch name: renovate/macos-26.x
  • Merge into: master
  • Upgrade macos to 26
chore(deps): update dependency msw to v3
  • Schedule: ["at any time"]
  • Branch name: renovate/msw-3.x
  • Merge into: master
  • Upgrade msw to sha512-/74rddlgCmlHvrXUkuYKoUjDJTiP4Nrz2uyIpOTLtxJNCS+2yY+DlLfzzRUc61cvRjCo6Jvi2+vRNZyZQa1j4A==
chore(deps): update dependency node to v24
  • Schedule: ["at any time"]
  • Branch name: renovate/node-24.x
  • Merge into: master
  • Upgrade node to 24
  • Upgrade node to 24.21.0
  • Upgrade node to 24-bookworm
  • Upgrade @types/node to sha512-aS3/DG0oM05K0RIXXP+hKjinGG5IgSSVGzswZxW3O0sS3pH4/fycXundUC9XsszgKCk4gHXylTEK6hyFxVxnoQ==
chore(deps): update dependency typescript to v7
  • Schedule: ["at any time"]
  • Branch name: renovate/typescript-7.x
  • Merge into: master
  • Upgrade typescript to sha512-8FYau96o3NKOhbjKi/qNvG/W5jhzxkbdm5sj9AbZ/5T5sWqn3hJgLfGx27sRKZWTvyzCP8dLRBTf5tBTSRVUNA==
chore(deps): update dependency ubuntu to v26
  • Schedule: ["at any time"]
  • Branch name: renovate/ubuntu-26.x
  • Merge into: master
  • Upgrade ubuntu to 26.04
  • Upgrade ubuntu to 26.04-arm
  • Upgrade ubuntu to 26.04
chore(deps): update dependency vitest to v5
  • Schedule: ["at any time"]
  • Branch name: renovate/major-vitest-monorepo
  • Merge into: master
  • Upgrade vitest to sha512-xMw97S3rjdtj5dkVat7jCsqWBpvchs3RlpQctUqwJD0KkERk40vz2fJ77lDwW/Vzh/pk18eItYAzkodhSes3jQ==
chore(deps): update github artifact actions (major)
  • Schedule: ["at any time"]
  • Branch name: renovate/major-github-artifact-actions
  • Merge into: master
  • Upgrade actions/download-artifact to 3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c
  • Upgrade actions/upload-artifact to 043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
fix(deps): update dependency @​modelcontextprotocol/ext-apps to v2
  • Schedule: ["at any time"]
  • Branch name: renovate/modelcontextprotocol-ext-apps-2.x
  • Merge into: master
  • Upgrade @modelcontextprotocol/ext-apps to sha512-Tn+4+cyhO4f4cQSDxNyLiIfEE+qlTTuIbWBJB8JTinEXOhDYgCT4wDTQplxD9MBYZH5pCYGC59GaxiwIT4bu8w==
fix(deps): update dependency lucide-react to v1
  • Schedule: ["at any time"]
  • Branch name: renovate/major-lucide-monorepo
  • Merge into: master
  • Upgrade lucide-react to sha512-TUgPtl5ZI9WgxOcbu4ckaC5B3l1qxPQrCMgb6OfUB9owx/OvSJfcf93SMgUWAxRw5/1XDfh9uI5F5iNGXCcGDQ==
fix(deps): update dependency react-router to v8
  • Schedule: ["at any time"]
  • Branch name: renovate/major-react-router-monorepo
  • Merge into: master
  • Upgrade react-router to sha512-JtydAkBvU9UTEe5qNC+POhu+ZBNM7rlKY2IegwXc7Idj7xfRG16x5RZrw3mju+XlqBxfvb2ky9P3jUp9WyWC1g==
fix(deps): update dependency zod to v4
  • Schedule: ["at any time"]
  • Branch name: renovate/zod-4.x
  • Merge into: master
  • Upgrade zod to sha512-v5l/aFXZQeai4awLbOpSoHecE9UiMrnfx75tEXLjNonXVARxQ5mOeipTjROUchszUNCqnE+hqAMujRsRHsut2Q==

🚸 PR creation will be limited to maximum 2 per hour, so it doesn't swamp any CI resources or overwhelm the project. See docs for prHourlyLimit for details.


Warning

Please correct - or verify that you can safely ignore - these dependency lookup failures before you merge this PR.

  • Could not determine new digest for update (github-tags package dtolnay/rust-toolchain)

Files affected: .github/workflows/ci.yml, .github/workflows/distribution-acceptance.yml, .github/workflows/release-beta.yml, .github/workflows/release.yml


❓ Got questions? Check out Renovate's Docs, particularly the Getting Started section.
If you need any further assistance then you can also request help here.


This PR was generated by Mend Renovate. View the repository job log.

@changeset-bot

changeset-bot Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: ddeff93

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 potential issue.

1 flag not posted on this PR by your GitHub settings — view it in Devin Review. (Configure)

Devin Review

Comment thread renovate.json
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": [
"config:recommended"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Rust dependency updates cannot refresh the lockfile

When Renovate updates a Rust dependency, cargo update encounters pnpm-vendored git sources that reject updates inside this checkout. Rust update PRs cannot carry a refreshed Cargo.lock.

Learn more

Cargo dependency updates need a refreshed lockfile. The committed Cargo source configuration replaces crates.io and pinned git sources with pnpm-vendored directories. The documented release lockfile updater runs Cargo outside the checkout specifically because cargo update refuses those replacements when run inside it. With default Cargo management, an update that needs a lockfile refresh cannot use the same working-directory setup as ordinary repositories.

Example: If a newer rusqlite is proposed for the workspace, an in-checkout Cargo update fails against the vendored sources rather than refreshing Cargo.lock for the PR.

Recommended fix: Configure Renovate's Cargo update process to resolve outside the checkout with the pinned toolchain, or explicitly disable Cargo management until a compatible lockfile-refresh path is available. Validate with an actual Rust dependency update that changes Cargo.lock and passes the frozen pnpm install.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants