-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdefault.json
More file actions
112 lines (112 loc) · 5.03 KB
/
Copy pathdefault.json
File metadata and controls
112 lines (112 loc) · 5.03 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": [
"config:recommended",
"helpers:pinGitHubActionDigests",
":enablePreCommit"
],
"timezone": "Europe/Paris",
"schedule": ["before 7am on monday"],
"prConcurrentLimit": 5,
"minimumReleaseAge": "14 days",
"customManagers": [
{
"description": "Renovate has no manager for the Ubuntu image of Read the Docs builds, so it follows the Ubuntu releases of Docker Hub.",
"customType": "regex",
"managerFilePatterns": ["/(^|/)\\.readthedocs\\.ya?ml$/"],
"matchStrings": ["os:\\s*[\"']?ubuntu-(?<currentValue>\\d{2}\\.\\d{2})[\"']?"],
"depNameTemplate": "readthedocs/ubuntu",
"packageNameTemplate": "ubuntu",
"datasourceTemplate": "docker",
"versioningTemplate": "ubuntu"
}
],
"packageRules": [
{
"description": "Our packages are libraries. The >= floors in [project.dependencies] are a compatibility contract with downstream users, so Renovate only refreshes uv.lock and never raises a floor. Floors are raised by hand, when the code starts relying on a newer API.",
"matchManagers": ["pep621"],
"rangeStrategy": "update-lockfile"
},
{
"description": "build-system.requires is not recorded in uv.lock, so update-lockfile would freeze the build backend forever. Widen the bound instead.",
"matchManagers": ["pep621"],
"matchDepTypes": ["build-system.requires"],
"rangeStrategy": "widen"
},
{
"description": "One pull request per repository for every non-major Python update.",
"matchManagers": ["pep621"],
"matchUpdateTypes": ["minor", "patch"],
"groupName": "python dependencies",
"automerge": true
},
{
"description": "One pull request per repository for GitHub Actions. Digests stay pinned and the trailing # vX.Y.Z comment is kept in sync.",
"matchManagers": ["github-actions"],
"matchUpdateTypes": ["minor", "patch", "digest"],
"groupName": "github actions",
"automerge": true
},
{
"description": "One pull request per repository for pre-commit hook revisions.",
"matchManagers": ["pre-commit"],
"matchUpdateTypes": ["minor", "patch"],
"groupName": "pre-commit hooks",
"automerge": true
},
{
"description": "The python-scim packages are ours, so their new releases skip the cooldown meant for third-party releases, as uv's exclude-newer-package does in each project.",
"matchDatasources": ["pypi"],
"matchPackageNames": ["scim2-models", "scim2-client", "scim2-server", "scim2-cli", "scim2-tester", "pytest-scim2-server"],
"minimumReleaseAge": null
},
{
"description": "This preset is ours, so its new tags skip the cooldown meant for third-party releases. Minor and major versions of the preset are adopted through a reviewed pull request in each repository.",
"matchManagers": ["renovate-config"],
"matchDepNames": ["python-scim/renovate-config"],
"minimumReleaseAge": null,
"automerge": false
},
{
"description": "Patch versions of the preset are automerged. Only administrators can push the tags of this repository.",
"matchManagers": ["renovate-config"],
"matchDepNames": ["python-scim/renovate-config"],
"matchUpdateTypes": ["patch"],
"automerge": true
},
{
"description": "uv builds the releases with its bundled backend only when its version matches the uv_build range of build-system.requires, so the uv of setup-uv, the uv container image and that range move together in one pull request.",
"matchPackageNames": ["astral-sh/uv", "docker.io/astral/uv", "uv-build"],
"groupName": "uv",
"automerge": true
},
{
"description": "Read the Docs only provides the LTS releases of Ubuntu. The Ubuntu tags of Docker Hub are pushed again at every rebuild, so the cooldown would hold them forever. Moving to a new Ubuntu release is a major update, so it still waits for a human.",
"matchDepNames": ["readthedocs/ubuntu"],
"allowedVersions": "/^\\d[02468]\\.04$/",
"minimumReleaseAge": null
},
{
"description": "GitHub runner labels have no release date, so the cooldown would hold them forever. Moving to a new Ubuntu release is a major update, so it still waits for a human.",
"matchDatasources": ["github-runners"],
"minimumReleaseAge": null
},
{
"description": "Major updates are never grouped and never automerged: each one gets its own pull request and a human review.",
"matchUpdateTypes": ["major"],
"automerge": false
}
],
"lockFileMaintenance": {
"description": "Weekly full refresh of uv.lock, which is the only way transitive dependencies ever move.",
"enabled": true,
"automerge": true,
"schedule": ["before 7am on monday"]
},
"vulnerabilityAlerts": {
"description": "Security fixes bypass the weekly schedule and the 14 day cooldown, and always wait for a human.",
"schedule": ["at any time"],
"minimumReleaseAge": null,
"automerge": false
}
}