Skip to content

Pin Renovate Maven lookups to the registry hosting each package - #20

Merged
rubensworks merged 1 commit into
masterfrom
claude/friendly-davinci-quklvj
Sep 12, 2026
Merged

rubensworks merged 1 commit into
masterfrom
claude/friendly-davinci-quklvj

Conversation

@rubensworks

Copy link
Copy Markdown
Member

Companion to CyclopsMC/packtests#73, which fixes the same problem in the pack tests repo.

Why this repo is affected too

Renovate runs in packtests have been aborting with External host error causing abort - skipping since around Sep 6. The cause is a 429 Too Many Requests from Maven Central, which Renovate turns into an ExternalHostError that takes down the whole run before any lookup or update happens.

This repo is exposed the same way, and more directly than the other infobook repos: its settings.xml lists Central explicitly alongside github, modmaven, cursemaven and creeperhost, and the Maven datasource uses registryStrategy = "merge", so all five are queried for each of the 12 deps. On top of that, cleanResult in modules/manager/maven/extract.js appends Central to every Maven dep unconditionally, so removing it from settings.xml alone would not help.

(Line references are from renovate@44.82.3, the current release.)

What changed

  1. registryUrls package rules, so each groupId is only looked up in the registry that actually serves it. This takes Central out of the lookup path entirely, which is what prevents the abort, and cuts 5 registry requests per dep down to 1.

    groupId registry
    org.cyclops.* https://maven.pkg.github.com/CyclopsMC/packages
    mekanism https://modmaven.dev/
    com.refinedmods.refinedstorage https://maven.creeperhost.net/
    curse.maven https://www.cursemaven.com/

    There is no curse.maven dep here today, but the cursemaven profile is active in settings.xml, so the rule is included to keep a future CurseForge dep off Central from day one.

  2. A hostRule for repo.maven.apache.org with abortOnError: false and abortIgnoreStatusCodes: [429], as a backstop. See the caveat below.

  3. The config migration Renovate was reporting: matchPackagePrefixes: ["org.cyclops."] is now matchPackageNames: ["org.cyclops.{/,}**"].

The rubensworks/renovate-presets:js extend, enabledManagers, both automerge rules (including the versioning regex on the Maven one), the existing refinedstorage-neoforge allowedVersions rule, and the github-actions major setting are all unchanged.

Why refinedstorage goes to creeperhost

maven.creeperhost.net is not the obvious upstream choice, but it is the only registry in this settings.xml that serves refinedstorage-neoforge at all. It is not on modmaven, and maven.refinedmods.com does not resolve. Conversely creeperhost is stale for mekanism (1.21-10.6.7.54 there vs 1.21.1-10.7.19.85 on modmaven), so mekanism is mapped to modmaven instead. Picking one registry for both without checking would have quietly frozen one of them.

Caveat: the hostRule is a backstop, not the fix

I checked this rather than assuming it, and it does not do what it looks like it does. In util/http/http.js the ExternalHostError conversion is gated on abortOnError being truthy, and abortOnError is already falsy by default, so setting it to false is a no-op, and abortIgnoreStatusCodes is only consulted when abortOnError is true. The abort we actually hit is thrown later and unconditionally by the Maven datasource's own Central special case in modules/datasource/maven/util.js. No hostRule suppresses it.

So change 1 is the real fix. The hostRule is kept only as a harmless backstop for non-Central hosts, and carries an in-file description saying so, so nobody later mistakes it for working protection.

If you want a hard guarantee instead, {"matchHost": "repo.maven.apache.org", "enabled": false} does work: a disabled host raises a plain host-disabled error that the Maven datasource classifies as unknown and swallows, never reaching the Central special case. I left it out because its failure mode is silent, but say the word and I will add it.

Validation

  • Fetched the exact .pom for every non-Cyclops coordinate in modpack.pom.xml from its mapped registry: mekanism:Mekanism:1.21.1-10.7.18.84 from modmaven and refinedstorage-neoforge:2.0.9 from creeperhost both return HTTP 200. No mapping is guessed.
  • Checked the glob patterns against Renovate's own matchRegexOrGlobList: all 12 deps match exactly one registry rule, so none is left on the multi-registry default and none matches two rules. The migrated "Cyclops packages" group rule still matches all 10 Cyclops deps.
  • npx --yes --package renovate -- renovate-config-validator --strict passes on the new config. The same command on master exits 1 with Config migration necessary.

🤖 Generated with Claude Code

https://claude.ai/code/session_01N6hkW22Va1tk2EqxDguWG4


Generated by Claude Code

Renovate's Maven manager appends Maven Central to every Maven dependency
and the datasource queries every registry in settings.xml for every dep.
When Central answers 429, the datasource raises an ExternalHostError and
the whole run aborts before any lookup or update. This is what has been
aborting runs in packtests since around Sep 6, and this repo has the same
multi-registry settings.xml, Central included.

- Restrict lookups per groupId: org.cyclops.* to our GitHub Packages
  registry, mekanism to modmaven, refinedstorage to creeperhost (the only
  registry here carrying its current versions), curse.maven to cursemaven.
  Central is no longer in the lookup path at all.
- Add a hostRule for repo.maven.apache.org as a backstop. Its description
  records that it does not actually suppress the Central abort, since the
  Maven datasource throws unconditionally for that host.
- Migrate matchPackagePrefixes to matchPackageNames in "Cyclops packages",
  which Renovate was reporting as a needed config migration.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N6hkW22Va1tk2EqxDguWG4
@rubensworks
rubensworks merged commit c59dbe9 into master Sep 12, 2026
2 checks passed
@rubensworks
rubensworks deleted the claude/friendly-davinci-quklvj branch September 12, 2026 12:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant