Skip to content

chore(renovate): weekly grouped updates, gate runtime majors - #68

Open
manast wants to merge 1 commit into
mainfrom
chore/quieter-renovate
Open

manast wants to merge 1 commit into
mainfrom
chore/quieter-renovate

Conversation

@manast

@manast manast commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Why

Renovate opens far more PRs than anyone can review (nandu alone opened about 20 in two days). Every PR needs an approving review under our SOC 2 rulesets, so the volume has to come down, not the bar.

What this changes

Before After
A PR per package, any day One weekly PR with all non-major updates (npm + GitHub Actions), Monday morning (Europe/Madrid)
Runtime majors open automatically Runtime majors (incl. overrides/resolutions, which hit every consumer) are only created after ticking them on the Dependency Dashboard issue
Dev/CI majors any day Dev/CI majors: one PR per package, at most once a month
Brand-new releases proposed immediately minimumReleaseAge: 3 days: a release must be 3 days old before Renovate proposes it (protects against compromised or yanked releases)
Lockfile drift Weekly lock file maintenance
At most 5 open Renovate PRs, 2 new per hour

Security fixes are unchanged: vulnerability alerts (GitHub + OSV) still open PRs immediately, ignoring the schedule and the release-age wait, and get a security label.

The daily automated Renovate review keeps running on top of this: it merges what passes, and labels the rest Need human with a reason.

Before merging

  • I couldn't run renovate-config-validator from my environment (the npm registry blocks the renovate package there). All options used are standard Renovate options. Renovate validates the config when it next runs and opens a "Config Validation" issue if anything is off.
  • This PR was opened from the manast account, so the ruleset requires someone else to approve it.

Repo-specific notes

This replaces the "group everything into one PR" config (#58). With every update in a single PR, one runtime major or failing test (as in #65: bullmq 6, ioredis 6, typebox 0.34, failing Bun tests) blocks all updates, including safe patches. The new config keeps the low volume (one weekly non-major PR), but majors no longer hold everything else back.

After merging, close #65. Renovate will recreate the safe part as the weekly non-major PR and list the majors on the Dependency Dashboard.

🤖 Generated with Claude Code

https://claude.ai/code/session_013btshYMGsbCH2dibYhx8qS


Generated by Claude Code

Group non-major updates into one weekly PR, move dev/CI majors to a
monthly schedule, require Dependency Dashboard approval for runtime
majors, and wait 3 days before proposing new releases. Security fixes
keep bypassing the schedule.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013btshYMGsbCH2dibYhx8qS
Copilot AI balanced review requested due to automatic review settings October 4, 2026 08:49

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The new schedules use Renovate’s deprecated natural-language syntax instead of the supported cron format.

Review effort: Balanced
Findings: 3 Medium severity

Open (3)
What changed in this PR

Reconfigures Renovate to reduce dependency-update noise while preserving immediate security remediation.

Changes:

  • Groups non-major updates into a weekly PR.
  • Gates runtime majors and schedules tooling majors monthly.
  • Adds release-age, lockfile-maintenance, and PR limits.
File Description
renovate.json Defines the revised Renovate scheduling, grouping, approval, and security policies.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread renovate.json
"timezone": "Europe/Madrid",
"schedule": [
"before 6am"
"before 7am on monday"
Comment thread renovate.json
"lockFileMaintenance": {
"enabled": true,
"schedule": [
"before 7am on monday"
Comment thread renovate.json
"major"
],
"schedule": [
"before 7am on the first day of the month"
@manast manast mentioned this pull request Oct 5, 2026
1 task
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants