Skip to content

Renovate config#1

Merged
mnonnenmacher merged 3 commits intomainfrom
renovate
Apr 2, 2026
Merged

Renovate config#1
mnonnenmacher merged 3 commits intomainfrom
renovate

Conversation

@mnonnenmacher
Copy link
Copy Markdown
Member

See the commit messages for details.

Let Renovate enable automerge for PRs that contain non-major updates to
reduce the amount of clicks required to merge dependency updates. Note
that these PRs still need to be approved and pass CI checks before they
are merged.

Signed-off-by: Martin Nonnenmacher <martin.nonnenmacher@doubleopen.org>
@mnonnenmacher mnonnenmacher enabled auto-merge (rebase) April 2, 2026 10:55
},
{
"matchDatasources": ["npm"],
"minimumReleaseAge": "5 days"
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

IIRC @willebra argued it should be rather 7 days, and I tend to agree.

Due to the frequent supply chain attacks in the NPM ecosystem, delay
updates of NPM packages by 7 days to reduce the risk of updating to
compromised versions.

Signed-off-by: Martin Nonnenmacher <martin.nonnenmacher@doubleopen.org>
Signed-off-by: Martin Nonnenmacher <martin.nonnenmacher@doubleopen.org>
@mnonnenmacher mnonnenmacher merged commit f04996f into main Apr 2, 2026
1 check passed
@mnonnenmacher mnonnenmacher deleted the renovate branch April 2, 2026 11:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants