Skip to content

chore: run Renovate weekly; Dependabot owns security PRs - #625

Merged
DhavalRepo18 merged 1 commit into
mainfrom
chore/renovate-weekly
Oct 6, 2026
Merged

DhavalRepo18 merged 1 commit into
mainfrom
chore/renovate-weekly

Conversation

@ShuxinLin

Copy link
Copy Markdown
Collaborator

Description

Renovate and Dependabot were both opening security PRs for the same packages. We tried turning off Dependabot security updates in the repo settings, but GitHub refused because of IBM's enforced security configuration:

422: An enforced security configuration prevented modifying dependabot security updates enablement.

So this PR gives each bot its own job:

  • Dependabot: security PRs (required by IBM), opened as soon as an advisory is published. Alerts stay on.
  • Renovate: weekly version updates only.

Changes to renovate.json:

  • schedule:weekly: Renovate opens PRs only before 4am UTC on Mondays. Before this, it had no schedule.
  • group:allNonMajor: one PR for all minor and patch updates. Each major update still gets its own PR.
  • :maintainLockFilesWeekly: a weekly uv.lock refresh, which picks up patched versions of packages we only depend on indirectly.
  • vulnerabilityAlerts.enabled: false: Renovate stops opening [SECURITY] PRs, so they aren't duplicated with Dependabot's.

Checked with renovate-config-validator --strict: passed.

This PR does not fix the open critical Dependabot alerts tracked in #580. That needs a separate lockfile upgrade.

Changes

  • Dependency update (uv lock)
  • Documentation / Tutorial update
  • Refactoring (no logic change)
  • CI / bot configuration

Checklist

  • I have signed off my commits (DCO).

IBM's enforced security configuration keeps Dependabot security updates
on, and the repo cannot turn them off. Renovate was also opening security
PRs, so the same package got two PRs.

- schedule:weekly: version update PRs only before 4am UTC on Mondays
- group:allNonMajor: one PR for all minor/patch updates; majors stay separate
- :maintainLockFilesWeekly: weekly uv.lock refresh to pick up patched
  transitive dependencies
- vulnerabilityAlerts disabled: Dependabot owns security PRs

Signed-off-by: Shuxin Lin <linshuhsin@gmail.com>
@ShuxinLin
ShuxinLin requested a review from DhavalRepo18 October 6, 2026 20:33
@DhavalRepo18
DhavalRepo18 merged commit 7137628 into main Oct 6, 2026
8 checks passed
@ShuxinLin
ShuxinLin deleted the chore/renovate-weekly branch October 6, 2026 22:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants