Skip to content
Draft
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions default.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"description": "WAVE org-wide Renovate preset. Every wave-av repo extends this via `local>wave-av/.github`. Named default.json (NOT renovate.json) because Renovate resolves a preset to default.json first and only falls back to renovate.json with a deprecation warning.",
"enabled": false,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2: enabled: false disables Renovate entirely for every repo that extends this preset, not just routine PR churn: vulnerability/OSV security PRs and the dependency dashboard stop too. This conflicts with org-inherited-config.json, which explicitly enables vulnerabilityAlerts for the whole org. If the pause targets CI churn from routine bumps, confirm that freezing security updates for these ~5 repos during the CI-down window is acceptable; if not, prefer a toggle that keeps vulnerability alerts flowing (e.g., disable via packageRules/managers or reconcile the Mend-hosted dashboard setting per affected repo).

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At default.json, line 4:

<comment>`enabled: false` disables Renovate entirely for every repo that extends this preset, not just routine PR churn: vulnerability/OSV security PRs and the dependency dashboard stop too. This conflicts with org-inherited-config.json, which explicitly enables `vulnerabilityAlerts` for the whole org. If the pause targets CI churn from routine bumps, confirm that freezing security updates for these ~5 repos during the CI-down window is acceptable; if not, prefer a toggle that keeps vulnerability alerts flowing (e.g., disable via packageRules/managers or reconcile the Mend-hosted dashboard setting per affected repo).</comment>

<file context>
@@ -1,6 +1,7 @@
 {
   "$schema": "https://docs.renovatebot.com/renovate-schema.json",
   "description": "WAVE org-wide Renovate preset. Every wave-av repo extends this via `local>wave-av/.github`. Named default.json (NOT renovate.json) because Renovate resolves a preset to default.json first and only falls back to renovate.json with a deprecation warning.",
+  "enabled": false,
   "extends": [
     "config:recommended",
</file context>

"extends": [
"config:recommended",
":dependencyDashboard",
Expand Down
Loading