|
1 | 1 | { |
2 | 2 | "$schema": "https://docs.renovatebot.com/renovate-schema.json", |
3 | 3 | "extends": [ |
4 | | - "config:recommended" |
5 | | - ], |
6 | | - "dependencyDashboard": true, |
7 | | - "pinDigests": true, |
8 | | - "osvVulnerabilityAlerts": true, |
9 | | - "labels": [ |
10 | | - "dependencies" |
11 | | - ], |
12 | | - "vulnerabilityAlerts": { |
13 | | - "labels": [ |
14 | | - "dependencies", |
15 | | - "security" |
16 | | - ], |
17 | | - "minimumReleaseAge": "0 days", |
18 | | - "automerge": true |
19 | | - }, |
20 | | - "packageRules": [ |
21 | | - { |
22 | | - "description": "Major updates: open PR immediately, assign for manual review and merge — no auto-merge", |
23 | | - "matchUpdateTypes": [ |
24 | | - "major" |
25 | | - ], |
26 | | - "automerge": false, |
27 | | - "reviewers": [ |
28 | | - "mbologna" |
29 | | - ] |
30 | | - }, |
31 | | - { |
32 | | - "description": "Group patch updates per package manager; hold 7 days to let the community catch supply-chain attacks before auto-merging on green CI", |
33 | | - "matchUpdateTypes": [ |
34 | | - "patch" |
35 | | - ], |
36 | | - "minimumReleaseAge": "7 days", |
37 | | - "groupName": "patch updates ({{manager}})", |
38 | | - "groupSlug": "patch-{{manager}}", |
39 | | - "automerge": true, |
40 | | - "automergeStrategy": "squash" |
41 | | - }, |
42 | | - { |
43 | | - "description": "Group digest updates per package manager; hold 7 days (same as patch) before auto-merging on green CI", |
44 | | - "matchUpdateTypes": [ |
45 | | - "digest" |
46 | | - ], |
47 | | - "minimumReleaseAge": "7 days", |
48 | | - "groupName": "digest updates ({{manager}})", |
49 | | - "groupSlug": "digest-{{manager}}", |
50 | | - "automerge": true, |
51 | | - "automergeStrategy": "squash" |
52 | | - }, |
53 | | - { |
54 | | - "description": "Group minor updates per package manager; hold 14 days to let the community catch supply-chain attacks before auto-merging on green CI", |
55 | | - "matchUpdateTypes": [ |
56 | | - "minor" |
57 | | - ], |
58 | | - "minimumReleaseAge": "14 days", |
59 | | - "groupName": "minor updates ({{manager}})", |
60 | | - "groupSlug": "minor-{{manager}}", |
61 | | - "automerge": true, |
62 | | - "automergeStrategy": "squash" |
63 | | - }, |
64 | | - { |
65 | | - "description": "Security/CVE updates: bypass age gate, jump the queue with prPriority 10, automerge immediately on green CI", |
66 | | - "matchCategories": [ |
67 | | - "security" |
68 | | - ], |
69 | | - "minimumReleaseAge": "0 days", |
70 | | - "prPriority": 10, |
71 | | - "automerge": true |
72 | | - } |
| 4 | + "config:recommended", |
| 5 | + "github>mbologna/renovate-config" |
73 | 6 | ] |
74 | 7 | } |
0 commit comments