Skip to content

Pin Renovate Maven lookups to the registry hosting each package - #11

Merged
rubensworks merged 1 commit into
masterfrom
claude/friendly-davinci-quklvj
Sep 12, 2026
Merged

rubensworks merged 1 commit into
masterfrom
claude/friendly-davinci-quklvj

Conversation

@rubensworks

Copy link
Copy Markdown
Member

Companion to CyclopsMC/packtests#73, which fixes the same problem in the pack tests repo.

Why this repo is affected too

Renovate runs in packtests have been aborting with External host error causing abort - skipping since around Sep 6. The cause is a 429 Too Many Requests from Maven Central, which Renovate turns into an ExternalHostError that takes down the whole run before any lookup or update happens.

It would be easy to assume this repo is safe, since its settings.xml declares only GitHub Packages and no Central. That assumption is wrong. In modules/manager/maven/extract.js, cleanResult appends Maven Central to every Maven dependency's registryUrls unconditionally, whatever settings.xml says. The datasource then uses registryStrategy = "merge", so Central is queried for both org.cyclops deps on every run, and a 429 from it aborts this repo's run exactly as it does in packtests.

(Line references are from renovate@44.82.3, the current release.)

What changed

  1. registryUrls package rule restricting org.cyclops.* to https://maven.pkg.github.com/CyclopsMC/packages, the only registry that actually serves it. This takes Central out of the lookup path entirely, which is what prevents the abort.
  2. A hostRule for repo.maven.apache.org with abortOnError: false and abortIgnoreStatusCodes: [429], as a backstop. See the caveat below.
  3. The config migration Renovate was reporting: matchPackagePrefixes: ["org.cyclops."] is now matchPackageNames: ["org.cyclops.{/,}**"].

The rubensworks/renovate-presets:js extend, enabledManagers, both automerge rules (including the versioning regex on the Maven one), and the github-actions major setting are all unchanged.

Caveat: the hostRule is a backstop, not the fix

I checked this rather than assuming it, and it does not do what it looks like it does. In util/http/http.js the ExternalHostError conversion is gated on abortOnError being truthy, and abortOnError is already falsy by default, so setting it to false is a no-op, and abortIgnoreStatusCodes is only consulted when abortOnError is true. The abort we actually hit is thrown later and unconditionally by the Maven datasource's own Central special case in modules/datasource/maven/util.js. No hostRule suppresses it.

So change 1 is the real fix. The hostRule is kept only as a harmless backstop for non-Central hosts, and carries an in-file description saying so, so nobody later mistakes it for working protection.

If you want a hard guarantee instead, {"matchHost": "repo.maven.apache.org", "enabled": false} does work: a disabled host raises a plain host-disabled error that the Maven datasource classifies as unknown and swallows, never reaching the Central special case. I left it out because its failure mode is silent, but say the word and I will add it.

Validation

  • Checked the glob pattern against Renovate's own matchRegexOrGlobList: both org.cyclops.cyclopscore:cyclopscore-1.21.1-neoforge and org.cyclops.evilcraft:evilcraft-1.21.1-neoforge match the new registry rule and the migrated "Cyclops packages" group rule, so grouping behaviour is preserved.
  • npx --yes --package renovate -- renovate-config-validator --strict passes on the new config. The same command on master exits 1 with Config migration necessary.

🤖 Generated with Claude Code

https://claude.ai/code/session_01N6hkW22Va1tk2EqxDguWG4


Generated by Claude Code

Renovate's Maven manager appends Maven Central to every Maven dependency
regardless of settings.xml, and the datasource queries every registry for
every dep. When Central answers 429, the datasource raises an
ExternalHostError and the whole run aborts before any lookup or update.
This is what has been aborting runs in packtests since around Sep 6, and
this repo is exposed to the same failure even though its settings.xml only
declares GitHub Packages.

- Restrict org.cyclops.* lookups to our GitHub Packages registry, so
  Central is no longer in the lookup path at all.
- Add a hostRule for repo.maven.apache.org as a backstop. Its description
  records that it does not actually suppress the Central abort, since the
  Maven datasource throws unconditionally for that host.
- Migrate matchPackagePrefixes to matchPackageNames in "Cyclops packages",
  which Renovate was reporting as a needed config migration.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N6hkW22Va1tk2EqxDguWG4
@rubensworks
rubensworks merged commit ccd8935 into master Sep 12, 2026
2 checks passed
@rubensworks
rubensworks deleted the claude/friendly-davinci-quklvj branch September 12, 2026 12:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant