Skip to content

chore(renovate): pause org preset (enabled: false) — draft until CI restored - #46

Draft
yakimoto wants to merge 1 commit into
mainfrom
chore/ci-prepay-hygiene
Draft

yakimoto wants to merge 1 commit into
mainfrom
chore/ci-prepay-hygiene

Conversation

@yakimoto

@yakimoto yakimoto commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

What

Adds one key to the org Renovate preset default.json: "enabled": false. Nothing else changes. The extends, hostRules, packageRules and schedule blocks are the same as before.

Why

This is a temporary pause of Renovate while the org's CI is paused. There are currently 499 open Renovate PRs and 273 open Dependabot PRs across the org (a paginated GraphQL search, asserted against the total issueCount of 1,498 open PRs). When CI comes back, every one of those would rebase and trigger a full CI run at the same moment. Pausing Renovate first means CI capacity goes to real work and not to a rebase storm.

Why enabled: false and not prConcurrentLimit: 0 / prHourlyLimit: 0

In Renovate, 0 on either limit means no limit. It does not mean zero PRs. Setting them to 0 would lift the throttle instead of pausing. enabled: false is the documented way for a preset to turn Renovate off for every repo that extends it.

Scope, stated honestly

This preset is only reached by repos that extend local>wave-av/.github. At origin default today that is 5 repos, including this one, and together they hold 13 of the 499 open Renovate PRs. Most of the Renovate PRs are in repos that have no Renovate config file at all. Those repos are driven by the hosted app's own settings, not by this file. The app-level pause in the Mend dashboard is the lever that covers the whole fleet, and it is a separate, operator-run step.

When it takes effect

Only after this PR is merged. It is a draft on purpose, and it should stay draft until CI is restored and the operator decides the timing.

How to revert

Close this PR unmerged. If it was merged, delete the single "enabled": false, line from default.json. No other state changes.

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Summary by Sourcery

Pause Renovate through the shared organization preset while CI is unavailable.

Enhancements:

  • Temporarily disable Renovate for repositories using the organization preset until CI capacity is restored.

Chores:

  • Add the Renovate enabled flag to the shared default preset.

Review in cubic

Temporary: prevents a rebase storm across repos extending this preset.
Revert by removing the single enabled:false line.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 23, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Sep 23, 2026

Copy link
Copy Markdown
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

This draft adds a single enabled: false setting to the organization Renovate preset, pausing Renovate only for repositories that extend the preset; it does not pause the hosted app fleet-wide and should remain unmerged until CI is restored and the operator coordinates timing.

File-Level Changes

Change Details Files
Temporarily disables Renovate for repositories inheriting the organization preset by adding the documented preset-level pause flag.
  • Add "enabled": false to the default Renovate preset.
  • Leave existing extends, hostRules, packageRules, and schedule configuration unchanged.
default.json

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 1 file

Confidence score: 3/5

  • default.json sets enabled: false, which disables Renovate for every repository extending the preset—including vulnerability/OSV security PRs and the dependency dashboard; scope this setting so routine PR churn is controlled without suppressing security updates.
Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="default.json">

<violation number="1" location="default.json:4">
P2: `enabled: false` disables Renovate entirely for every repo that extends this preset, not just routine PR churn: vulnerability/OSV security PRs and the dependency dashboard stop too. This conflicts with org-inherited-config.json, which explicitly enables `vulnerabilityAlerts` for the whole org. If the pause targets CI churn from routine bumps, confirm that freezing security updates for these ~5 repos during the CI-down window is acceptable; if not, prefer a toggle that keeps vulnerability alerts flowing (e.g., disable via packageRules/managers or reconcile the Mend-hosted dashboard setting per affected repo).</violation>
</file>

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread default.json
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"description": "WAVE org-wide Renovate preset. Every wave-av repo extends this via `local>wave-av/.github`. Named default.json (NOT renovate.json) because Renovate resolves a preset to default.json first and only falls back to renovate.json with a deprecation warning.",
"enabled": false,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2: enabled: false disables Renovate entirely for every repo that extends this preset, not just routine PR churn: vulnerability/OSV security PRs and the dependency dashboard stop too. This conflicts with org-inherited-config.json, which explicitly enables vulnerabilityAlerts for the whole org. If the pause targets CI churn from routine bumps, confirm that freezing security updates for these ~5 repos during the CI-down window is acceptable; if not, prefer a toggle that keeps vulnerability alerts flowing (e.g., disable via packageRules/managers or reconcile the Mend-hosted dashboard setting per affected repo).

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At default.json, line 4:

<comment>`enabled: false` disables Renovate entirely for every repo that extends this preset, not just routine PR churn: vulnerability/OSV security PRs and the dependency dashboard stop too. This conflicts with org-inherited-config.json, which explicitly enables `vulnerabilityAlerts` for the whole org. If the pause targets CI churn from routine bumps, confirm that freezing security updates for these ~5 repos during the CI-down window is acceptable; if not, prefer a toggle that keeps vulnerability alerts flowing (e.g., disable via packageRules/managers or reconcile the Mend-hosted dashboard setting per affected repo).</comment>

<file context>
@@ -1,6 +1,7 @@
 {
   "$schema": "https://docs.renovatebot.com/renovate-schema.json",
   "description": "WAVE org-wide Renovate preset. Every wave-av repo extends this via `local>wave-av/.github`. Named default.json (NOT renovate.json) because Renovate resolves a preset to default.json first and only falls back to renovate.json with a deprecation warning.",
+  "enabled": false,
   "extends": [
     "config:recommended",
</file context>

@wave-bugbot

wave-bugbot Bot commented Sep 30, 2026

Copy link
Copy Markdown

🟢 WAVE BugBot — clear

No confident findings on the changed lines.

Local review · $0 inference · wave-dispatch

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant