chore(deps): own the Renovate policy in-repo and fix inherited config gaps - #136
Merged
Merged
Conversation
renovate.json extended local>oapi-codegen/renovate-config, a repo owned by the upstream oapi-codegen org rather than doordash-oss, tracked at its unpinned default branch. Anyone with write access there could change how dependencies are updated here, which is the same mutable-reference exposure we just removed from the workflows. The preset's contents are inlined so the policy is reviewable in-repo; only Renovate's own built-in presets remain referenced, since those are unavoidable when using Renovate at all. Also addresses three problems the inherited config caused: - Both Dependency Dashboard issues (#90, #93) could not be closed: Renovate reopens a dashboard by design, so dependencyDashboard is turned off instead. - Root-module bumps failed CI every time. examples/ replaces the root module, so its go.sum went stale on every root bump while gomodTidy only tidied the module it updated. Grouping gomod updates keeps both modules in one PR. - golangci-lint was never tracked at all: the inherited Makefile manager looked for a `curl install.sh` line this repo does not use, so the pin sat at v2.12.2 unnoticed. The replacement matches the actual go install line. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>
This was referenced Sep 18, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Takes ownership of this repo's Renovate policy and fixes three problems the inherited config was causing.
Why
renovate.jsonextendedlocal>oapi-codegen/renovate-config— a public repo owned by the upstreamoapi-codegenorg, notdoordash-oss— tracked at its unpinned default branch, chaining further togithub>oapi-codegen/renovate-config:user. Anyone with write access there changes how dependencies are updated in this repo. That is the same mutable-reference exposure #130 just removed from the workflows, one level up.This inlines the preset's contents so the policy is reviewable here. Renovate's own built-in presets (
config:best-practices,helpers:pinGitHubActionDigestsToSemver) stay referenced, since depending on renovatebot is unavoidable when using Renovate at all. No behaviour from the upstream preset is dropped except the two managers that never matched this repo (see below).What else this fixes
1. The Dependency Dashboard issues could not be closed (#90, #93)
Renovate treats the dashboard as a managed artifact and reopens it on the next run:
"dependencyDashboard": falseis the actual off switch. This closes both, since both installations read this file.2. Root-module bumps failed CI every time, by construction
examples/carriesreplace github.com/doordash-oss/oapi-codegen-dd/v3 => ../, so itsgo.sumgoes stale whenever a root dependency moves. The inheritedpostUpdateOptions: ["gomodTidy"]does tidy — but only the module it updated. That is why #106 and #113 sat red for two weeks with:Adding
groupName: "go modules"to thegomodrule keeps both modules in one branch, sogomodTidyruns across both. It also collapses what was ten simultaneous opengo.modPRs into one, which is what #129 did by hand.3. golangci-lint was never tracked
The inherited manager looked for a
curl .../golangci-lint/install.shline. This repo usesgo install ...@v2.12.2(Makefile:24), so nothing matched and the pin was silently unmanaged — it sat at v2.12.2 while v2.13.2 exists. That is why the Go 1.27 attempt in #122 walked into a staticcheck IR panic with no advance warning.Replaced with a manager that matches the real line. Verified against the actual
Makefile:4. The Go-directive guard now covers CI
The inherited config already intends this — it carries
constraintsFiltering: "strict"described as "Ensure that dependency updates do not bump thegodirective". But that rule scopes tomatchManagers: ["gomod"], and #122 bumpedgo-versioninci.yml, which thegithub-actionsmanager owns (depName: go,depType: uses-with, per #122's own body). So the guard existed and simply did not reach CI. The new rule closes that gap.Dropped
Two inherited custom managers that match nothing in this repo:
curl install.shMakefile manager (replaced, above)# yaml-language-server: $schema=https://raw.githubusercontent.com/oapi-codegen/oapi-codegen/.... This repo uses relative schema paths (../../configuration-schema.json), so it never matched.Verification
renovate-config-validator(renovate@latest, as repo config):The custom manager regex was checked against the real
Makefileunder node (Renovate's regex flavour), output above.Not addressed here
Two Renovate apps are installed on this repo,
doordash-renovateanddoordash-renovate-staging. That is why there were two dashboards, and why #115/#131 duplicated #116-#121: each installation keeps its own PR state, so closing one app's PR does not stop the other proposing the same update. Turning off the dashboard hides the symptom; uninstalling one app is a GitHub settings change and the real fix.Also still unpinned and therefore unmanageable by Renovate:
gosec@latest(ci.yml:49) andgo-licenses@latest(Makefile:112).🤖 Generated with Claude Code