Renovate #86570
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| --- | |
| # Renovate this repository when dispatched by dispatch-renovate.yaml, on PR/push events | |
| # for the required status check, or on manual trigger. | |
| name: Renovate | |
| on: | |
| issues: | |
| types: [edited] | |
| pull_request: | |
| # `opened`, `reopened`, and `synchronize` ensure the `Renovate / Renovate` required | |
| # status check appears on PRs that fro-bot opens against `main` (e.g., wiki ingest | |
| # PRs from survey workflows). Without these, the workflow never fires on PR | |
| # creation and the required check never posts, leaving the PR blocked until | |
| # someone manually edits the PR to generate an `edited` event. `edited` is kept | |
| # for manual re-trigger workflows (PR body/comment edits). | |
| types: [opened, reopened, synchronize, edited] | |
| push: | |
| branches-ignore: [main] | |
| workflow_dispatch: | |
| inputs: | |
| log-level: | |
| description: Log level for Renovate | |
| required: false | |
| type: string | |
| default: debug | |
| print-config: | |
| description: Log the fully-resolved Renovate config for each repository, plus fully-resolved presets. | |
| required: false | |
| type: boolean | |
| default: false | |
| workflow_run: | |
| branches: [main] | |
| types: [completed] | |
| workflows: [Main] | |
| permissions: | |
| contents: read | |
| jobs: | |
| renovate: | |
| name: Renovate | |
| if: >- | |
| (github.event.action == 'edited' && !contains(github.actor, '[bot]')) || | |
| ( | |
| github.event_name != 'workflow_run' || | |
| github.event.workflow_run.conclusion == 'success' | |
| ) | |
| secrets: | |
| APPLICATION_ID: ${{ secrets.APPLICATION_ID }} | |
| APPLICATION_PRIVATE_KEY: ${{ secrets.APPLICATION_PRIVATE_KEY }} | |
| uses: bfra-me/.github/.github/workflows/renovate.yaml@55859d58bf2922cecdde2a079f8ba8a1c2615566 # v4.34.0 | |
| with: | |
| # INERT as of bfra-me/renovate-action 10.42.1 — this does NOT disable autodiscover. | |
| # Kept to declare intent (cross-repo dispatch belongs to dispatch-renovate.yaml), not | |
| # because it works. Two independent upstream reasons, both verified 2026-09-20: | |
| # 1. action.yaml interpolates the value textually into a double-quoted shell | |
| # assignment (`user_global_config="${{ env.global_config }}"`), so the JSON's own | |
| # quotes are stripped, `jq` validation fails, and the step logs | |
| # `Invalid JSON syntax in user global-config` then falls back to base config at | |
| # exit 0. Any JSON value breaks identically; there is no quoting of ours that fixes it. | |
| # 2. Even parsed, it would lose: the reusable workflow computes `autodiscover` from the | |
| # repository name and passes it as an explicit action input. This repo is named | |
| # `.github`, so autodiscover is forced on for schedule/dispatch runs against `main`. | |
| # Net effect: sweeps reach org repos absent from `metadata/renovate.yaml` `with-renovate`. | |
| # Do not "fix" by deleting this input or reshaping the JSON — the fix is upstream. | |
| global-config: '{"autodiscover": false}' | |
| log-level: ${{ inputs.log-level || 'debug' }} | |
| path-filters: >- | |
| [ | |
| '.github/workflows/renovate.yaml', | |
| '.github/renovate.json5', | |
| 'default.json', | |
| ] | |
| print-config: ${{ inputs.print-config || false }} |