Skip to content

Renovate

Renovate #86570

Workflow file for this run

---
# Renovate this repository when dispatched by dispatch-renovate.yaml, on PR/push events
# for the required status check, or on manual trigger.
name: Renovate
on:
issues:
types: [edited]
pull_request:
# `opened`, `reopened`, and `synchronize` ensure the `Renovate / Renovate` required
# status check appears on PRs that fro-bot opens against `main` (e.g., wiki ingest
# PRs from survey workflows). Without these, the workflow never fires on PR
# creation and the required check never posts, leaving the PR blocked until
# someone manually edits the PR to generate an `edited` event. `edited` is kept
# for manual re-trigger workflows (PR body/comment edits).
types: [opened, reopened, synchronize, edited]
push:
branches-ignore: [main]
workflow_dispatch:
inputs:
log-level:
description: Log level for Renovate
required: false
type: string
default: debug
print-config:
description: Log the fully-resolved Renovate config for each repository, plus fully-resolved presets.
required: false
type: boolean
default: false
workflow_run:
branches: [main]
types: [completed]
workflows: [Main]
permissions:
contents: read
jobs:
renovate:
name: Renovate
if: >-
(github.event.action == 'edited' && !contains(github.actor, '[bot]')) ||
(
github.event_name != 'workflow_run' ||
github.event.workflow_run.conclusion == 'success'
)
secrets:
APPLICATION_ID: ${{ secrets.APPLICATION_ID }}
APPLICATION_PRIVATE_KEY: ${{ secrets.APPLICATION_PRIVATE_KEY }}
uses: bfra-me/.github/.github/workflows/renovate.yaml@55859d58bf2922cecdde2a079f8ba8a1c2615566 # v4.34.0
with:
# INERT as of bfra-me/renovate-action 10.42.1 — this does NOT disable autodiscover.
# Kept to declare intent (cross-repo dispatch belongs to dispatch-renovate.yaml), not
# because it works. Two independent upstream reasons, both verified 2026-09-20:
# 1. action.yaml interpolates the value textually into a double-quoted shell
# assignment (`user_global_config="${{ env.global_config }}"`), so the JSON's own
# quotes are stripped, `jq` validation fails, and the step logs
# `Invalid JSON syntax in user global-config` then falls back to base config at
# exit 0. Any JSON value breaks identically; there is no quoting of ours that fixes it.
# 2. Even parsed, it would lose: the reusable workflow computes `autodiscover` from the
# repository name and passes it as an explicit action input. This repo is named
# `.github`, so autodiscover is forced on for schedule/dispatch runs against `main`.
# Net effect: sweeps reach org repos absent from `metadata/renovate.yaml` `with-renovate`.
# Do not "fix" by deleting this input or reshaping the JSON — the fix is upstream.
global-config: '{"autodiscover": false}'
log-level: ${{ inputs.log-level || 'debug' }}
path-filters: >-
[
'.github/workflows/renovate.yaml',
'.github/renovate.json5',
'default.json',
]
print-config: ${{ inputs.print-config || false }}