Skip to content

ci: enable renovate for all dependencies [NOTASK] - #81

Merged
cristianrcv merged 1 commit into
masterfrom
arnaualcazar/renovate-migration
Oct 7, 2026
Merged

cristianrcv merged 1 commit into
masterfrom
arnaualcazar/renovate-migration

Conversation

@arnaualcazar

Copy link
Copy Markdown
Member

Context

Renovate already runs against this repo from seqeralabs/renovate-runner. The shared instance scans every seqeralabs/* repo but only updates GitHub Actions, unless the repo's own config sets enabledManagers. This repo has no Dependabot config, so Go modules and the dev docker-compose images are not being updated today.

Goal

Enable Renovate for all dependencies that can reasonably be bumped:

  • Add renovate.json with enabledManagers: gomod, github-actions, docker-compose.
  • Weekly cadence (Sunday-night window), same as the other migrated repos.
  • Groups: one PR for Go module minor/patch updates (gomodTidy runs after each update), one for docker-compose minor/patch updates, and one for actions (minor, patch, pin, digest). This includes the go-version of actions/setup-go and the goreleaser version in the workflows.
  • Left out: the Dockerfile (FROM scratch, nothing to bump), manifests/deployment.yml (our own cr.seqera.io/public/staticreg image) and the Tailwind binary pinned in the Makefile (its download URL is paired with a SHA256, which Renovate cannot update together).
  • The go directive in go.mod is not bumped; it moves by hand together with the CI and Docker toolchains.

Commit type, the 5-day release-age wait, vulnerability alerts and the action rules (no majors, renovate-actions label) come from the runner config.

Caveats

  • Checked locally: renovate-config-validator --strict passes, and renovate --platform=local --dry-run=extract detects go.mod (11 direct deps plus the go directive, which is disabled; indirect deps are disabled by default), 3 workflow files, and the postgres and registry images in docker-compose.yml. The Dockerfile and manifests are not detected.
  • There are no open Dependabot PRs, so nothing to close.
  • The extract dry-run doesn't check which updates would be proposed. The real check is the first Renovate run after merging.

ToDo list

  • After merge, trigger seqeralabs / Renovate in renovate-runner and check the Dependency Dashboard issue lists the Go and docker-compose deps.

@cristianrcv
cristianrcv merged commit 8497787 into master Oct 7, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants