From 1a63b259a7abea54876e9a72418a8fad52af3b79 Mon Sep 17 00:00:00 2001 From: Franck Nijhof Date: Sun, 27 Sep 2026 13:18:30 +0000 Subject: [PATCH] Move dependency updates from Dependabot to Renovate --- .github/dependabot.yml | 14 ------------ .github/renovate.json | 50 ++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 50 insertions(+), 14 deletions(-) delete mode 100644 .github/dependabot.yml create mode 100644 .github/renovate.json diff --git a/.github/dependabot.yml b/.github/dependabot.yml deleted file mode 100644 index ea733fdb..00000000 --- a/.github/dependabot.yml +++ /dev/null @@ -1,14 +0,0 @@ -version: 2 -updates: -- package-ecosystem: "github-actions" - directory: "/" - schedule: - interval: daily - time: "06:00" - open-pull-requests-limit: 10 -- package-ecosystem: gomod - directory: "/" - schedule: - interval: daily - time: "06:00" - open-pull-requests-limit: 10 diff --git a/.github/renovate.json b/.github/renovate.json new file mode 100644 index 00000000..452a55a7 --- /dev/null +++ b/.github/renovate.json @@ -0,0 +1,50 @@ +{ + "$schema": "https://docs.renovatebot.com/renovate-schema.json", + "extends": ["config:recommended", "helpers:pinGitHubActionDigests"], + + "enabledManagers": ["github-actions", "gomod"], + + "minimumReleaseAge": "3 days", + "postUpdateOptions": ["gomodTidy"], + + "semanticCommits": "disabled", + "labels": ["dependencies"], + + "packageRules": [ + { + "description": "Label Go module updates like Dependabot did", + "matchManagers": ["gomod"], + "addLabels": ["go"] + }, + { + "description": "Label GitHub Actions updates like Dependabot did", + "matchManagers": ["github-actions"], + "addLabels": ["github_actions"] + }, + { + "description": "The golang.org/x modules are released together every month", + "matchPackageNames": ["golang.org/x/**"], + "groupName": "golang.org/x", + "groupSlug": "golang-x" + }, + { + "description": "Leave the Go version in go.mod alone. Moving to a new Go release is a deliberate change, together with the version in the workflows.", + "matchManagers": ["gomod"], + "matchDepTypes": ["golang", "toolchain"], + "enabled": false + }, + { + "description": "Leave runner labels and action version inputs alone, Dependabot never updated those", + "matchManagers": ["github-actions"], + "matchDepTypes": ["github-runner", "uses-with"], + "enabled": false + }, + { + "description": "Our own actions that follow a branch (like home-assistant/actions@master) float on purpose. Pinning them would open a digest PR in every repository for each change to them. Our own actions on a version tag are pinned like any other.", + "matchManagers": ["github-actions"], + "matchPackageNames": ["home-assistant/**"], + "matchCurrentValue": "/^(dev|main|master)$/", + "pinDigests": false + } + ] +}