Repository navigation
chore: harden renovate config validator and pin renovate@44 - #5611
openshift-merge-bot[bot] merged 6 commits into
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #5611 +/- ##
==========================================
- Coverage 72.77% 66.19% -6.59%
==========================================
Files 68 61 -7
Lines 786 633 -153
Branches 113 96 -17
==========================================
- Hits 572 419 -153
Misses 213 213
Partials 1 1
Continue to review full report in Codecov by Harness.
🚀 New features to boost your workflow:
|
|
The container image build workflow finished with status: |
|
The container image build workflow finished with status: |
|
The container image build workflow finished with status: |
|
The container image build workflow finished with status: |
|
The container image build workflow finished with status: |
|
The container image build workflow finished with status: |
Align the workflow with rhdh-plugins hardening and pin renovate to major 44 so the npx cache refreshes. Co-authored-by: Cursor <cursoragent@cursor.com>
Avoid npx (Sonar S6505) by using ghcr.io/renovatebot/renovate:44 instead of latest for intentional major pinning. Co-authored-by: Cursor <cursoragent@cursor.com>
Lock ghcr.io/renovatebot/renovate to 44.145.1 via sha256 for reproducible CI. Co-authored-by: Cursor <cursoragent@cursor.com>
Use tag@digest form and re-enable digest updates only for ghcr.io/renovatebot/renovate. Co-authored-by: Cursor <cursoragent@cursor.com>
renovate-config-validator is offline-only and does not need a GitHub token. Co-authored-by: Cursor <cursoragent@cursor.com>
Checkout failed with EACCES on /__w/_temp because the renovate image user cannot write runner state files. Match renovatebot's container options so the job runs as UID 1001. Co-authored-by: Cursor <cursoragent@cursor.com>
e60f1f7 to
6826560
Compare
|
e51f3cf
into
redhat-developer:main



Summary
.github/workflows/renovate-checks.yamlsimilar to rhdh-plugins#3756: least-privilegepermissions,persist-credentials: false, andGITHUB_COM_TOKENfor validation.renovate@44so the npx cache is forced to refresh on the new major (v44 was an accidental major with no real breaking changes).Test plan
.github/renovate.jsonnpx --yes --package renovate@44 -- renovate-config-validator --strict .github/renovate.jsonsucceeds locally or in CIMade with Cursor