Repository navigation
Conversation
Group non-major updates into one weekly PR, move dev/CI majors to a monthly schedule, require Dependency Dashboard approval for runtime majors, and wait 3 days before proposing new releases. Security fixes keep bypassing the schedule. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013btshYMGsbCH2dibYhx8qS
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The new schedules use Renovate’s deprecated natural-language syntax instead of the supported cron format.
Review effort: Balanced
Findings: 3
Open (3)
What changed in this PR
Reconfigures Renovate to reduce dependency-update noise while preserving immediate security remediation.
Changes:
- Groups non-major updates into a weekly PR.
- Gates runtime majors and schedules tooling majors monthly.
- Adds release-age, lockfile-maintenance, and PR limits.
| File | Description |
|---|---|
renovate.json |
Defines the revised Renovate scheduling, grouping, approval, and security policies. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| "timezone": "Europe/Madrid", | ||
| "schedule": [ | ||
| "before 6am" | ||
| "before 7am on monday" |
| "lockFileMaintenance": { | ||
| "enabled": true, | ||
| "schedule": [ | ||
| "before 7am on monday" |
| "major" | ||
| ], | ||
| "schedule": [ | ||
| "before 7am on the first day of the month" |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Why
Renovate opens far more PRs than anyone can review (nandu alone opened about 20 in two days). Every PR needs an approving review under our SOC 2 rulesets, so the volume has to come down, not the bar.
What this changes
overrides/resolutions, which hit every consumer) are only created after ticking them on the Dependency Dashboard issueminimumReleaseAge: 3 days: a release must be 3 days old before Renovate proposes it (protects against compromised or yanked releases)Security fixes are unchanged: vulnerability alerts (GitHub + OSV) still open PRs immediately, ignoring the schedule and the release-age wait, and get a
securitylabel.The daily automated Renovate review keeps running on top of this: it merges what passes, and labels the rest
Need humanwith a reason.Before merging
renovate-config-validatorfrom my environment (the npm registry blocks therenovatepackage there). All options used are standard Renovate options. Renovate validates the config when it next runs and opens a "Config Validation" issue if anything is off.manastaccount, so the ruleset requires someone else to approve it.Repo-specific notes
This replaces the "group everything into one PR" config (#58). With every update in a single PR, one runtime major or failing test (as in #65: bullmq 6, ioredis 6, typebox 0.34, failing Bun tests) blocks all updates, including safe patches. The new config keeps the low volume (one weekly non-major PR), but majors no longer hold everything else back.
After merging, close #65. Renovate will recreate the safe part as the weekly non-major PR and list the majors on the Dependency Dashboard.
🤖 Generated with Claude Code
https://claude.ai/code/session_013btshYMGsbCH2dibYhx8qS
Generated by Claude Code