Repository navigation
fix(#3482): exclude vulnerability PRs from grouped patch updates - #3485
Conversation
|
🤖 Finished Review · ✅ Success · Started 2:29 PM UTC · Completed 2:42 PM UTC Commit: |
Codecov Report✅ All modified and coverable lines are covered by tests.
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
ReviewConfig-only re-review: the Previous runReviewFindingsMedium
Next steps:
Previous run (2)ReviewConfig-only change (12 lines in
Security scan of the diff for injection / Unicode steganography / bidi overrides / permission-manifest changes found nothing — the only non-ASCII byte is a U+2014 em dash in the human-written comment. Net posture is a small improvement (faster surfacing + clear routing labels for CVE fixes). Remaining concerns are about PR-tracking hygiene rather than the diff itself, and should be addressed before merge. Prior-review provenance validation failed ( FindingsLow
Next steps:
Previous run (3)ReviewFindingsCritical
Medium
Low
Info
Next steps:
Previous run (4)ReviewFindingsMedium
Low
Labels: PR modifies Renovate configuration for vulnerability alert handling |
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
cuipinghuo
left a comment
There was a problem hiding this comment.
Reviewed and adopting for EC-2084. Resolved the merge conflict against current main by keeping only the intended EC-2084 additions (packageRules vulnerability-ungroup rule + vulnerabilityAlerts labels/schedule); dropped the re-added helpers:pinGitHubActionDigests extends line since main removed it in 520e13c (EC-2080) as the org-wide config already provides it. Net diff vs main is exactly the two intended blocks.
|
🤖 Finished Review · ✅ Success · Started 1:50 PM UTC · Completed 1:59 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $4.32 |
|
Risk Assessment: low (1/5) DetailsConfig-only PR to non-protected renovate.json by a bot with low churn and small blast radius; partial issue resolution modestly elevates Tier 3 but Tier 1 dominates, preserving prior low score. Previous runRisk Assessment: low (1/5) DetailsConfig-only PR touching a single non-protected, non-security-sensitive file (11 changed lines) authored by a bot — Tier 1 sub-scores are all 1. Linked issue slightly elevates Tier 3 (2.5) because the PR admits it does not satisfy the issue’s stated validation criterion, but Tier 1 dominates the weighted average. Previous run (2)Risk Assessment: low (1/5) DetailsTiny additive renovate config change from a bot, fully scoped to a recent well-defined issue, on a low-churn config file that is trivially revertible. |
203f75c to
04b2664
Compare
cuipinghuo
left a comment
There was a problem hiding this comment.
Re-approving after amending the Sep-15 merge commit: conflict resolved against current main, and per review the redundant vulnerability-ungroup packageRule was dropped (Renovate already forces groupName: null for vulnerability alerts) with a documenting comment. Kept the useful vulnerabilityAlerts block (security label + immediate creation). Net diff vs main is just those changes.
|
🤖 Finished Review · ✅ Success · Started 2:15 PM UTC · Completed 2:23 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $3.90 |
|
🤖 Finished Review · ✅ Success · Started 3:31 AM UTC · Completed 3:38 AM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $3.05 |
cuipinghuo
left a comment
There was a problem hiding this comment.
Re-approving after the schedule-override drop (6c9b2b9). Final change is just the vulnerabilityAlerts labels block plus a documenting comment; the ungrouping packageRule and schedule override were correctly removed as no-ops (Renovate's built-in force block already handles both for vulnerability alerts).
6c9b2b9 to
b06a133
Compare
cuipinghuo
left a comment
There was a problem hiding this comment.
Re-approving after rebase onto latest main (single clean commit). Final change is just the vulnerabilityAlerts labels block + documenting comment. Rebase also re-triggers the previously-failing ec-main-enterprise-contract integration test (unrelated to this config-only change).
Superseded by updated review
reviewed and resolved |
reviewed and resolved |
b06a133 to
f414e03
Compare
|
🤖 Finished Review · ❌ Failure (ensuring provider "github-ro": provider create "github-ro" failed: exit status 1 (output: Error: × code: 'Client specified an invalid argument', message: "provider │ credentials are not declared by pr…) · Started 1:16 PM UTC · Completed 1:16 PM UTC Commit: Effort: high |
Add a vulnerabilityAlerts block so Renovate security/vulnerability update PRs are labeled `security` (and `renovate`) and are easy to spot and route. No packageRules ungrouping rule and no schedule override are added — both would be no-ops. Renovate's built-in force block already forces groupName: null and ignores the daily schedule for vulnerability alerts, outranking user config. A comment documents this. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
f414e03 to
bf784a2
Compare
|
🤖 Finished Review · ❌ Failure (ensuring provider "github-ro": provider create "github-ro" failed: exit status 1 (output: Error: × code: 'Client specified an invalid argument', message: "provider │ credentials are not declared by pr…) · Started 1:21 PM UTC · Completed 1:21 PM UTC Commit: Effort: high |
|
🤖 Finished Retro · ❌ Failure (ensuring provider "github-artifacts": provider create "github-artifacts" failed: exit status 1 (output: Error: × code: 'Client specified an invalid argument', message: "provider │ credentials are not…) · Started 1:38 PM UTC · Completed 1:38 PM UTC Commit: Effort: high |
What:
Add a
vulnerabilityAlertsblock torenovate.jsonthat labels Renovate security/vulnerability update PRs withsecurity(andrenovate) so CVE-fix PRs are easy to spot and route.No
packageRulesungrouping rule and noscheduleoverride are added — both would be no-ops. Renovate already keeps vulnerability fixes as standalone PRs and creates them immediately, because its built-inforceblock forcesgroupName: nulland ignores the dailyschedulefor vulnerability alerts, outranking user config. A comment in the file documents this.Why:
Security update PRs should be clearly labeled so they can be spotted and routed quickly. Renovate's defaults already handle ungrouping and immediate creation; labeling is the remaining gap this closes.
Note: the recurring autoclose of standalone security PRs stems from Renovate's update deduplication against a long-stalled grouped patch PR carrying the same bump — a separate root cause not addressed by grouping config, tracked separately.
Tickets:
#3482
Closes #3482