Skip to content

Commit

Permalink
Switch to renovate best-practices preset (#2724)
Browse files Browse the repository at this point in the history
to address the OpenSSF scorecard "Pinned-Dependencies" findings.
  • Loading branch information
silvestre authored Mar 8, 2024
1 parent 9f99be5 commit 88e318c
Showing 1 changed file with 17 additions and 5 deletions.
22 changes: 17 additions & 5 deletions renovate.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": [
"config:js-app",
"config:best-practices",
"regexManagers:dockerfileVersions",
":label(dependencies)",
":automergeAll"
Expand All @@ -26,96 +26,108 @@
},
{
"description": "Strip of v prefix from version number in certain github releases",
"packageNames": ["bosh-cli"],
"matchPackageNames": ["bosh-cli"],
"extractVersion": "^v(?<version>.*)$"
}
],
"nix": { "enabled": true },
"regexManagers": [
"nix": {"enabled": true},
"customManagers": [
{
"customType": "regex",
"fileMatch": ["\\.tool-versions$"],
"matchStrings": ["(^|\\n)act (?<currentValue>.+?)\\n"],
"depNameTemplate": "nektos/act",
"datasourceTemplate": "github-releases",
"extractVersionTemplate": "^v(?<version>\\S+)"
},
{
"customType": "regex",
"fileMatch": ["\\.tool-versions$"],
"matchStrings": ["(^|\\n)actionlint (?<currentValue>.+?)\\n"],
"depNameTemplate": "rhysd/actionlint",
"datasourceTemplate": "github-releases",
"extractVersionTemplate": "^v(?<version>\\S+)"
},
{
"customType": "regex",
"fileMatch": ["\\.tool-versions$"],
"matchStrings": ["(^|\\n)bosh (?<currentValue>.+?)\\n"],
"depNameTemplate": "cloudfoundry/bosh-cli",
"datasourceTemplate": "github-releases",
"extractVersionTemplate": "^v(?<version>\\S+)"
},
{
"customType": "regex",
"fileMatch": ["\\.tool-versions$"],
"matchStrings": ["(^|\\n)cf (?<currentValue>.+?)\\n"],
"depNameTemplate": "cloudfoundry/cli",
"datasourceTemplate": "github-releases",
"extractVersionTemplate": "^v(?<version>\\S+)"
},
{
"customType": "regex",
"fileMatch": ["\\.tool-versions$"],
"matchStrings": ["(^|\\n)concourse (?<currentValue>.+?)\\n"],
"depNameTemplate": "concourse/concourse",
"datasourceTemplate": "github-releases",
"extractVersionTemplate": "^v(?<version>\\S+)"
},
{
"customType": "regex",
"fileMatch": ["\\.tool-versions$"],
"matchStrings": ["(^|\\n)gcloud (?<currentValue>.+?)\\n"],
"depNameTemplate": "google/cloud-sdk",
"datasourceTemplate": "docker"
},
{
"customType": "regex",
"fileMatch": ["\\.tool-versions$"],
"matchStrings": ["(^|\\n)ginkgo (?<currentValue>.+?)\\n"],
"depNameTemplate": "onsi/ginkgo",
"datasourceTemplate": "github-releases",
"extractVersionTemplate": "^v(?<version>\\S+)"
},
{
"customType": "regex",
"fileMatch": ["\\.tool-versions$"],
"matchStrings": ["(^|\\n)golangci-lint (?<currentValue>.+?)\\n"],
"depNameTemplate": "golangci/golangci-lint",
"datasourceTemplate": "github-releases",
"extractVersionTemplate": "^v(?<version>\\S+)"
},
{
"customType": "regex",
"fileMatch": ["\\.tool-versions$"],
"matchStrings": ["(^|\\n)maven (?<currentValue>.+?)\\n"],
"depNameTemplate": "apache/maven",
"datasourceTemplate": "github-releases"
},
{
"customType": "regex",
"fileMatch": ["\\.tool-versions$"],
"matchStrings": ["(^|\\n)terraform-lsp (?<currentValue>.+?)\\n"],
"depNameTemplate": "juliosueiras/terraform-lsp",
"datasourceTemplate": "github-releases",
"extractVersionTemplate": "^v(?<version>\\S+)"
},
{
"customType": "regex",
"fileMatch": ["\\.tool-versions$"],
"matchStrings": ["(^|\\n)terragrunt (?<currentValue>.+?)\\n"],
"depNameTemplate": "gruntwork-io/terragrunt",
"datasourceTemplate": "github-releases",
"extractVersionTemplate": "^v(?<version>\\S+)"
},
{
"customType": "regex",
"fileMatch": ["\\.tool-versions$"],
"matchStrings": ["(^|\\n)yq (?<currentValue>.+?)\\n"],
"depNameTemplate": "mikefarah/yq",
"datasourceTemplate": "github-releases",
"extractVersionTemplate": "^v(?<version>\\S+)"
}
],
"lockFileMaintenance": { "enabled": true },
"lockFileMaintenance": {"enabled": true},
"schedule": ["after 1am and before 7am every weekday"],
"timezone": "Europe/Berlin"
}

0 comments on commit 88e318c

Please sign in to comment.