The rules were copied into each app's renovate.json, so they were identical only by luck and a change meant six edits — the Testcontainers guard existed in two repos and not the other four. Apps now extend this. Also records the two majors that are blocked upstream rather than by our code: typescript-eslint peers at typescript <6.1, eslint-plugin-react peers at eslint <=9.7.
35 lines
1.6 KiB
JSON
35 lines
1.6 KiB
JSON
{
|
|
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
|
"description": "Shared preset for every app on the Bennett platform. Apps extend this rather than copying rules, so a change here reaches all of them.",
|
|
"extends": ["config:recommended"],
|
|
"packageRules": [
|
|
{
|
|
"description": "Bennett platform releases: our own code, already tested and Trivy-scanned before publish. Grouped into one PR and merged automatically so a fix reaches every app without manual work. Merging main triggers the build, which re-runs tests and re-scans; if either fails no image is pushed, so a bad bump cannot reach production.",
|
|
"matchPackageNames": ["net.thebennett.platform:**"],
|
|
"groupName": "bennett platform",
|
|
"automerge": true
|
|
},
|
|
{
|
|
"description": "Stay on Testcontainers 1.x. 2.0 renamed the module artifacts (postgresql, junit-jupiter), so the major bump does not just fail the build — its POM will not parse.",
|
|
"matchPackageNames": ["org.testcontainers:**"],
|
|
"matchUpdateTypes": ["major"],
|
|
"enabled": false
|
|
},
|
|
{
|
|
"description": "TypeScript 7 is gated by typescript-eslint, which peers at <6.1. Re-enable once it ships support; until then the PR only ever conflicts with itself.",
|
|
"matchPackageNames": ["typescript"],
|
|
"matchUpdateTypes": ["major"],
|
|
"enabled": false
|
|
},
|
|
{
|
|
"description": "ESLint 10 is gated by eslint-plugin-react, which peers at <=9.7.",
|
|
"matchPackageNames": ["eslint"],
|
|
"matchUpdateTypes": ["major"],
|
|
"enabled": false
|
|
}
|
|
],
|
|
"vulnerabilityAlerts": {
|
|
"labels": ["security"]
|
|
}
|
|
}
|