-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdefault.json
More file actions
181 lines (181 loc) · 9.81 KB
/
Copy pathdefault.json
File metadata and controls
181 lines (181 loc) · 9.81 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": [
"config:recommended"
],
"minimumReleaseAge": "4 days",
"commitMessagePrefix": "[RUN-0000]",
"dependencyDashboard": true,
"fetchChangeLogs": "off",
"rebaseWhen": "never",
"hostRules": [
{
"description": "Concentrating almost all Gradle lookups onto Maven Central (see registryUrls scoping below) increased request density enough to trip its rate limiter (429s). Throttle our own concurrency here instead of bursting and eating retry/backoff costs.",
"matchHost": "repo1.maven.org",
"concurrentRequestLimit": 4,
"maxRequestsPerSecond": 5
}
],
"vulnerabilityAlerts": {
"dependencyDashboardApproval": false
},
"packageRules": [
{
"description": "Defer major updates to manual selection from the Dependency Dashboard",
"matchUpdateTypes": ["major"],
"dependencyDashboardApproval": true
},
{
"description": "Group noisy Google Cloud client library revision bumps",
"matchPackageNames": ["/^com\\.google\\.apis:/", "/^com\\.google\\.cloud:/"],
"groupName": "google cloud clients"
},
{
"description": "google-cloud-container versions above 2.82.0 require protobuf-java 4.x, but protobufVersion is globally forced to 3.25.9 in build.gradle for CVE-2024-7254. Bumping past 2.82.0 causes NoClassDefFoundError (missing RuntimeVersion$RuntimeDomain) in GcpGkeResourceModelSpec - already reverted once in 2c6b381cbf and re-broke this branch when Renovate re-proposed it. Block until protobufVersion itself is bumped as its own validated change.",
"matchPackageNames": ["com.google.cloud:google-cloud-container"],
"enabled": false
},
{
"description": "Group routine Gradle minor/patch dependency bumps",
"matchManagers": ["gradle"],
"matchUpdateTypes": ["minor", "patch"],
"groupName": "gradle minor/patch dependencies"
},
{
"description": "Grails minors have a history of real behavioral changes despite semver, and grails-plugin-spring-security-core must move in lockstep with it — pull both out of the auto-grouped minor/patch bucket for manual review. Groovy is included here too: Grails dictates which Groovy line it's built against, and bumping groovyVersion independently caused classpath skew that broke the forked :rundeckapp:assetCompile JVM (rundeck#10448, ExceptionInInitializerError in GroovySystem.<clinit>). log4j2, asm, kotlin-stdlib, and ant joined the group in RUN-4809: Grails' base BOM manages all four as *strict* dependency-management constraints that plain resolutionStrategy.force can't override, so build.gradle force-overrides them via explicit dependencyManagement entries instead (documented inline there). Guava is BOM-managed the same way but has no dependencyManagement override, so it can't move independently at all: :enterprise exportedLibs follows guavaVersion while :rundeckapp's bootWar stays on the grails-base-bom version, and the WAR ends up with two guava (and two transitive jspecify) jars, failing verifyBuild's stem-uniqueness check. Whoever reviews a Grails bump here should also confirm those overrides still clear whatever floor the new grails-base-bom asserts, and that guavaVersion still matches it.",
"matchPackageNames": ["/^org\\.apache\\.grails:/", "/^org\\.apache\\.groovy:/", "/^org\\.apache\\.logging\\.log4j:/", "/^org\\.ow2\\.asm:/", "org.jetbrains.kotlin:kotlin-stdlib", "/^org\\.apache\\.ant:/", "com.google.guava:guava"],
"groupName": "grails framework (manual review required)",
"dependencyDashboardApproval": true
},
{
"description": "Spock's version suffix (e.g. -groovy-5.0) encodes the Groovy variant it's compiled against; that must move in lockstep with our own groovyVersion pin, not silently ride along on a 'minor' semver bump",
"matchPackageNames": ["/^org\\.spockframework:/"],
"groupName": "spock framework (manual review - groovy variant coupling)",
"dependencyDashboardApproval": true
},
{
"description": "jetty.version only forces jetty-util in core/build.gradle; every other Jetty artifact stays pinned wherever Spring Boot's BOM manages it. A 'minor' bump here (e.g. 12.0.x -> 12.1.x) can cross Jetty's own release-line boundary and produce a mixed-version classpath — must be reviewed and moved in lockstep with springBootVersion",
"matchPackageNames": ["/^org\\.eclipse\\.jetty/"],
"groupName": "jetty (manual review - Spring Boot BOM coupling)",
"dependencyDashboardApproval": true
},
{
"description": "bcprov-jdk18on shares the bouncyCastleVersion property with bcpkix/bcutil/bcmail/bctls-jdk18on (git-plugin, license-cli, rundeckpro-license, etc.), and those siblings don't always cut a patch release together — 1.85.2 was published for bcprov-jdk18on alone, which broke git-plugin's bcpkix-jdk18on resolution when Renovate bumped the shared property (PR #4922). Needs its own groupName, not just dependencyDashboardApproval: without one it stayed lumped into the 'gradle minor/patch dependencies' group below and rode along anyway (re-broke #4922 a second time). Gate on Dependency Dashboard approval rather than disabling outright, so this keeps surfacing instead of being silently forgotten; before approving, confirm bcpkix/bcutil/bcmail/bctls-jdk18on have all published the same version on Maven Central.",
"matchPackageNames": ["org.bouncycastle:bcprov-jdk18on"],
"groupName": "bouncy castle bcprov (manual review - patch cadence mismatch with siblings)",
"dependencyDashboardApproval": true
},
{
"description": "Keep the Jira REST client app/core artifacts in lockstep",
"matchPackageNames": ["/^com\\.atlassian\\.jira:jira-rest-java-client-/"],
"groupName": "atlassian jira rest client"
},
{
"description": "Group low-risk GitHub Actions updates",
"matchManagers": ["github-actions"],
"groupName": "github actions"
},
{
"description": "Never batch our own runner/sidecar artifact with unrelated updates",
"matchPackageNames": ["com.rundeck.sidecar:pd-runner-api"],
"groupName": null,
"automerge": false
},
{
"description": "Block packages Eng has flagged as too disruptive to auto-update",
"matchPackageNames": [
"jquery",
"/^@types\\/jquery$/",
"vue-eslint-parser",
"/^@vue\\/cli-/",
"storybook",
"/^@storybook\\//",
"vue-i18n",
"typescript",
"/^@typescript/",
"typescript-eslint",
"sass",
"sass-loader",
"/^com\\.h2database:/"
],
"enabled": false
},
{
"description": "Group ESLint ecosystem updates",
"matchPackageNames": ["/eslint/"],
"groupName": "eslint packages"
},
{
"description": "Group Jest ecosystem updates",
"matchPackageNames": ["jest", "ts-jest", "@types/jest"],
"groupName": "jest packages"
},
{
"description": "Group PrimeVue ecosystem updates",
"matchPackageNames": ["primevue", "primeicons", "@primeuix/themes"],
"groupName": "primevue packages"
},
{
"description": "Enable npm engine version updates (disabled by default in Renovate)",
"matchDepTypes": ["engines"],
"enabled": true
},
{
"description": "Group Node.js version (.nvmrc) with the npm engine pin so they update together",
"matchManagers": ["nvm", "npm"],
"matchDepNames": ["node", "npm"],
"groupName": "node and npm engine versions"
},
{
"description": "Default registry for the vast majority of Gradle dependencies (Spring, Netty, Jackson, JUnit, etc.) instead of checking every globally-declared repo (m2proxy, PackageCloud, Sonatype, Grails, Gradle Plugin Portal, ...) for every dependency. Only ~9% of our gradle deps are actually Grails/Groovy-namespaced, so grails.org is scoped separately below rather than checked for everything.",
"matchManagers": ["gradle"],
"registryUrls": [
"https://repo1.maven.org/maven2/"
]
},
{
"description": "Grails/Groovy-namespaced artifacts also need the Grails Maven repo",
"matchPackageNames": ["/^org\\.apache\\.grails:/", "/^org\\.grails\\.plugins:/", "/^org\\.apache\\.groovy:/"],
"registryUrls": [
"https://repo1.maven.org/maven2/",
"https://repo.grails.org/grails/core/"
]
},
{
"description": "Gradle plugin marker artifacts resolve via the Gradle Plugin Portal, not plain Maven Central",
"matchManagers": ["gradle"],
"matchDepTypes": ["plugin"],
"registryUrls": [
"https://plugins.gradle.org/m2/",
"https://repo1.maven.org/maven2/"
]
},
{
"description": "PagerDuty-internal runner/sidecar artifacts only exist on our PackageCloud feeds",
"matchPackageNames": ["/^com\\.rundeck\\.sidecar:/", "/^com\\.rundeck\\.runner:/"],
"registryUrls": [
"https://packagecloud.io/pagerduty/rundeckpro/maven2/",
"https://packagecloud.io/pagerduty/rundeckpro-test/maven2/",
"https://repo1.maven.org/maven2/"
]
},
{
"description": "org.rundeck artifacts also need the Sonatype Central snapshots feed and PackageCloud (plugins no longer publish to Maven Central)",
"matchPackageNames": ["/^org\\.rundeck[.:]/"],
"registryUrls": [
"https://packagecloud.io/pagerduty/rundeck-plugins/maven2/",
"https://repo1.maven.org/maven2/",
"https://central.sonatype.com/repository/maven-snapshots/",
"https://repo.grails.org/grails/core/"
]
},
{
"description": "Atlassian artifacts (Jira REST client, commonmark) need the internal Atlassian Maven proxy",
"matchPackageNames": ["/^com\\.atlassian[.:]/"],
"registryUrls": [
"https://m2proxy.atlassian.com/repository/public/",
"https://repo1.maven.org/maven2/"
]
}
]
}