Repository navigation
feat: integrate Renovate for automated dependency updates - #197
Conversation
|
Hi @ulgens Could you comment/review this PR ? Thank you |
17c0049 to
f80efba
Compare
|
Rebased on What changed
|
Add Renovate configuration with pip-compile support for automated dependency management. Configuration includes: - Explicit file patterns for main.txt, dev.txt, production.txt - Python 3.13 constraint matching Heroku runtime - Django/Wagtail ecosystem grouping with Monday scheduling - Intelligent automerge: only dev.txt patches, never production - Security updates prioritized with separate PRs - Rate limiting to avoid PR spam - Monthly lock file maintenance This setup is optimized for safe Heroku deployments with manual review required for production dependencies. Closes #187 Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
The previous config was written for the pip-compile workflow and pointed
at requirements/{main,dev,production}.txt, which no longer exist since
the migration to pyproject.toml + uv.lock (#247). It was a no-op.
- Drop the pip-compile / pip_requirements / pip_setup blocks; the pep621
manager (enabled by config:recommended) picks up pyproject.toml and
drives `uv lock` for uv.lock.
- Main vs dev split now uses depTypes instead of file paths:
[project.dependencies] -> "project.dependencies" (never automerged),
[dependency-groups] -> "dependency-groups" (patch automerge). pep621
keeps the PEP 735 group name only in managerData, so it cannot be
matched; "dev" is currently the only group. Dev patches get their own
group so automerge is not blocked by production deps on the same branch.
- Security: the vulnerability alert settings were inside a packageRule
restricted to patch updates (and to non-0.x versions), which excluded
fixes needing a minor bump. Move them to the top-level
vulnerabilityAlerts object with no update-type restriction. prPriority
is dropped: it is not allowed there, and vulnerability PRs already
bypass schedule and PR limits.
- Restrict the "All non-major dependencies" group to pep621 so Dockerfile
and GitHub Actions bumps are not mixed into the Monday Python group.
- Replace the removed matchPackagePatterns / excludePackagePatterns /
matchFiles options with matchPackageNames regexes and depTypes.
- Disable requires-python updates: Python is pinned to 3.13.x.
- Run lockFileMaintenance weekly instead of monthly: most dependencies in
pyproject.toml have no version specifier, so Renovate skips them
(skipReason "unspecified-version") and the uv.lock refresh is the only
way they get updated.
Validated with `renovate-config-validator --strict --no-global` and a
local `renovate --platform=local --dry-run=extract` run.
f80efba to
8e5fb21
Compare
pep621 has no manager-specific range strategy, so "auto" resolves to "replace". With "replace", a ">=" lower bound that already allows the new version produces no update at all, which would make the lower bounds added to pyproject.toml useless. "bump" raises the lower bound in pyproject.toml and updates uv.lock in the same PR. Checked with a local renovate dry-run on a copy with older locked versions: "replace" proposed nothing, while "bump" proposed boto3 >=1.43.90 -> >=1.43.102, requests >=2.33.0 -> >=2.34.2, etc.
|
Added Why both are needed: a local Renovate dry-run on a copy with older locked versions (
With the final config, the simulated branches are Note: Merge #197 and #248 together: either one alone doesn't change what Renovate does. |
- uv is versioned in three places (pep621 dev dependency "uv", Docker image "ghcr.io/astral-sh/uv", mise tool "astral-sh/uv"): group them in a single "uv" PR so they stay in sync. - Python is pinned to 3.13.x: the Docker base image, mise and .python-version only accept 3.13 (requires-python is already disabled). - Production runs PostgreSQL 17 on Heroku: CI and docker-compose stay on 17. Checked with a local renovate dry-run across all managers: the Dockerfile and mise uv bumps land on renovate/uv, and no Python 3.14 or Postgres 18 update is proposed.
|
Added three rules (
A local dry-run with all managers confirms the grouping, and no Python 3.14 or Postgres 18 PR is proposed. The one remaining major is The ruff pin is no longer an issue: #248 moves to ruff 0.16.9 and fixes the new lint findings. |
Overview
This PR integrates Renovate for automated dependency management, closing #187.
Following the migration to
uv, Renovate will automate dependency updates while maintaining our currentrequirements/*.in→requirements/*.txtpip-compile workflow.🔒 Configuration Highlights
Heroku-Safe Deployment Strategy
main.txt,dev.txt,production.txtIntelligent Grouping & Scheduling
Rate Limiting
Disabled Conflicting Managers
Per Renovate documentation, this prevents duplicate runs.
📋 What Happens Next?
renovate.jsonconfiguration🔗 References
✨ Benefits
task dependencies:upgrade🤖 Generated with Claude Code