From dfb2288fa3f1df7c42f20bb98328f2d17bff7593 Mon Sep 17 00:00:00 2001 From: Slavi Pantaleev Date: Tue, 25 Aug 2026 09:25:10 +0300 Subject: [PATCH] Renovate: merge routine updates by pushing, without pull requests ci.yml runs on `push: ["**"]`, so a Renovate branch is already compiled, linted with `clippy -D warnings` and unit-tested before anything reaches main; a red branch makes Renovate open a pull request instead of merging. That gate now covers the Dockerfile base too, via the build job added in the previous commit. Cargo, the Rust toolchain, prek and the workflows' own actions therefore merge by branch push. The local development images under etc/services/** do too, on a different justification recorded in the rule itself: CI does not run them and they reach no shipped artifact, so the worst case is a broken `just services-start`. Majors keep their pull request - the rule is deliberately last, so it overrides the others for every manager. Co-Authored-By: Claude Fable 5 --- renovate.json | 57 +++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 57 insertions(+) diff --git a/renovate.json b/renovate.json index 888f672..88315c1 100644 --- a/renovate.json +++ b/renovate.json @@ -5,5 +5,62 @@ ], "labels": [ "dependencies" + ], + "packageRules": [ + { + "description": "Cargo dependencies, the Rust toolchain pin, prek (via mise) and the workflows' own actions merge by pushing to main, without a pull request. ci.yml runs on `push: [\"**\"]`, so the Renovate branch itself is compiled, linted with `clippy -D warnings` and unit-tested first; a failure leaves the branch red and Renovate raises a pull request instead of merging.", + "matchManagers": [ + "cargo", + "rust-toolchain", + "mise", + "github-actions" + ], + "matchUpdateTypes": [ + "minor", + "patch", + "digest" + ], + "automerge": true, + "automergeType": "branch", + "platformAutomerge": false + }, + { + "description": "The release image's base (Dockerfile and Dockerfile.ci). Gated by ci.yml's docker-build job, which builds the image exactly as Publish does but with `push: false`, and which only runs when a Dockerfile actually changed.", + "matchManagers": [ + "dockerfile" + ], + "matchUpdateTypes": [ + "minor", + "patch", + "digest" + ], + "automerge": true, + "automergeType": "branch", + "platformAutomerge": false + }, + { + "description": "Local development service images under etc/services/** - the homeservers and LLM backends that `just services-start` brings up. They are never part of a shipped artifact and CI does not run them, so the justification here is blast radius rather than validation: the worst case is a broken local development stack, fixed by pinning back.", + "matchManagers": [ + "docker-compose" + ], + "matchFileNames": [ + "etc/services/**" + ], + "matchUpdateTypes": [ + "minor", + "patch", + "digest" + ], + "automerge": true, + "automergeType": "branch", + "platformAutomerge": false + }, + { + "description": "Major updates always get a pull request and a human. This is deliberately the last rule so that it overrides the automerge rules above for every manager.", + "matchUpdateTypes": [ + "major" + ], + "automerge": false + } ] }