Skip to content

Add renovate dependency updates (#2027) - #2116

Open
shivakunv wants to merge 1 commit into
release-src/compute-plane-services/nvca/v3.7from
backport-renovate-dependency-updates-nvca-v3.7
Open

shivakunv wants to merge 1 commit into
release-src/compute-plane-services/nvca/v3.7from
backport-renovate-dependency-updates-nvca-v3.7

Conversation

@shivakunv

@shivakunv shivakunv commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

(cherry picked from commit c8c73ff)

TL;DR

Add a self-hosted Renovate workflow to automate Go module dependency updates
in this repository. Today there is no dependabot.yml or renovate.json at
the repo root, and no bot has ever opened a PR here. Chart and image version
pins already get bumped automatically by chart-version-bump.yml and
stack-pin-bump.yml, but Go module dependencies (go.mod/go.sum) across
the roughly 35 native Go subtrees under src/, tools/, tests/, and
examples/ are manual .

For the Reviewer

  • .github/renovate.json added, scoped to enabledManagers: ["gomod"],
    targeting main, with non-major Go dependency bumps grouped into one PR
    and major bumps opened individually.

  • ignorePaths excludes vendor/**, the two upstream-owned subtrees
    (ess-agent, vault-plugin-secrets-jwt), and any vendored Go module whose
    full vendor/ rewrite on a dependency bump would exceed what GitHub's
    git/trees API accepts in one commit

For QA (optional for docs, build, test, refactor, ci, chore, style, and revert PRs)

verified it with cloned repo: https://github.com/shivakunv/nvcf/pulls
QA not needed

Issues

closes: #2026

Checklist

  • I am familiar with the Contributing Guidelines.
  • I have signed off my commits for Developer Certificate of Origin (DCO) compliance.
  • New or existing tests cover these changes.
  • The documentation is up to date with these changes.

Summary by CodeRabbit

  • Chores
    • Automated Go module dependency updates are configured to run daily at 09:00 UTC, with an option to trigger them manually.
    • Dependency update pull requests target the main branch and are grouped and labeled to make review easier.
    • Update volume is limited, and selected project paths are excluded from automated updates.
    • Minor, patch, and digest updates receive a consistent commit prefix.

Signed-off-by: Shiva Kumar (SW-CLOUD) <shivaku@nvidia.com>
Co-authored-by: Shiva Kumar <shiva@nvidia.com>
Co-authored-by: Anand Parthasarathi <259851807+apartha-nv@users.noreply.github.com>
(cherry picked from commit c8c73ff)
@shivakunv
shivakunv requested review from a team as code owners September 28, 2026 07:52
@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

🗂️ Base branches to auto review (1)
  • main

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: NVIDIA/nvcf/.coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 300bf69b-7d97-4c09-a5eb-bd8e37752779

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant