Conversation
Temporary: prevents a rebase storm across repos extending this preset. Revert by removing the single enabled:false line. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueComment |
Reviewer's guide (collapsed on small PRs)Reviewer's GuideThis draft adds a single File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
1 issue found across 1 file
Confidence score: 3/5
default.jsonsetsenabled: false, which disables Renovate for every repository extending the preset—including vulnerability/OSV security PRs and the dependency dashboard; scope this setting so routine PR churn is controlled without suppressing security updates.
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name="default.json">
<violation number="1" location="default.json:4">
P2: `enabled: false` disables Renovate entirely for every repo that extends this preset, not just routine PR churn: vulnerability/OSV security PRs and the dependency dashboard stop too. This conflicts with org-inherited-config.json, which explicitly enables `vulnerabilityAlerts` for the whole org. If the pause targets CI churn from routine bumps, confirm that freezing security updates for these ~5 repos during the CI-down window is acceptable; if not, prefer a toggle that keeps vulnerability alerts flowing (e.g., disable via packageRules/managers or reconcile the Mend-hosted dashboard setting per affected repo).</violation>
</file>
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
| { | ||
| "$schema": "https://docs.renovatebot.com/renovate-schema.json", | ||
| "description": "WAVE org-wide Renovate preset. Every wave-av repo extends this via `local>wave-av/.github`. Named default.json (NOT renovate.json) because Renovate resolves a preset to default.json first and only falls back to renovate.json with a deprecation warning.", | ||
| "enabled": false, |
There was a problem hiding this comment.
P2: enabled: false disables Renovate entirely for every repo that extends this preset, not just routine PR churn: vulnerability/OSV security PRs and the dependency dashboard stop too. This conflicts with org-inherited-config.json, which explicitly enables vulnerabilityAlerts for the whole org. If the pause targets CI churn from routine bumps, confirm that freezing security updates for these ~5 repos during the CI-down window is acceptable; if not, prefer a toggle that keeps vulnerability alerts flowing (e.g., disable via packageRules/managers or reconcile the Mend-hosted dashboard setting per affected repo).
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At default.json, line 4:
<comment>`enabled: false` disables Renovate entirely for every repo that extends this preset, not just routine PR churn: vulnerability/OSV security PRs and the dependency dashboard stop too. This conflicts with org-inherited-config.json, which explicitly enables `vulnerabilityAlerts` for the whole org. If the pause targets CI churn from routine bumps, confirm that freezing security updates for these ~5 repos during the CI-down window is acceptable; if not, prefer a toggle that keeps vulnerability alerts flowing (e.g., disable via packageRules/managers or reconcile the Mend-hosted dashboard setting per affected repo).</comment>
<file context>
@@ -1,6 +1,7 @@
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"description": "WAVE org-wide Renovate preset. Every wave-av repo extends this via `local>wave-av/.github`. Named default.json (NOT renovate.json) because Renovate resolves a preset to default.json first and only falls back to renovate.json with a deprecation warning.",
+ "enabled": false,
"extends": [
"config:recommended",
</file context>
🟢 WAVE BugBot — clearNo confident findings on the changed lines. Local review · $0 inference · wave-dispatch |
What
Adds one key to the org Renovate preset
default.json:"enabled": false. Nothing else changes. Theextends,hostRules,packageRulesandscheduleblocks are the same as before.Why
This is a temporary pause of Renovate while the org's CI is paused. There are currently 499 open Renovate PRs and 273 open Dependabot PRs across the org (a paginated GraphQL search, asserted against the total
issueCountof 1,498 open PRs). When CI comes back, every one of those would rebase and trigger a full CI run at the same moment. Pausing Renovate first means CI capacity goes to real work and not to a rebase storm.Why
enabled: falseand notprConcurrentLimit: 0/prHourlyLimit: 0In Renovate,
0on either limit means no limit. It does not mean zero PRs. Setting them to 0 would lift the throttle instead of pausing.enabled: falseis the documented way for a preset to turn Renovate off for every repo that extends it.Scope, stated honestly
This preset is only reached by repos that extend
local>wave-av/.github. At origin default today that is 5 repos, including this one, and together they hold 13 of the 499 open Renovate PRs. Most of the Renovate PRs are in repos that have no Renovate config file at all. Those repos are driven by the hosted app's own settings, not by this file. The app-level pause in the Mend dashboard is the lever that covers the whole fleet, and it is a separate, operator-run step.When it takes effect
Only after this PR is merged. It is a draft on purpose, and it should stay draft until CI is restored and the operator decides the timing.
How to revert
Close this PR unmerged. If it was merged, delete the single
"enabled": false,line fromdefault.json. No other state changes.🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by Sourcery
Pause Renovate through the shared organization preset while CI is unavailable.
Enhancements:
Chores: