default.json is a public preset consumed by every repo extending local>fro-bot/.github, but .github/workflows/main.yaml has no Renovate config validation step. A malformed rule ships org-wide with local validation as the only check.
This is not hypothetical for allowedVersions specifically: if a value fails all four parse branches, lookup/filter.ts throws CONFIG_VALIDATION for the entire repository config, not just the one dependency — so a single bad rule in the shared preset breaks Renovate for every consumer, not just the dep it targets.
Suggested addition to the Lint job:
- name: ✅ Validate Renovate config
run: pnpm dlx --package renovate renovate-config-validator --strict default.json .github/renovate.json5
Raised during review of #3791 and kept out of that PR because it modifies CI.
default.jsonis a public preset consumed by every repo extendinglocal>fro-bot/.github, but.github/workflows/main.yamlhas no Renovate config validation step. A malformed rule ships org-wide with local validation as the only check.This is not hypothetical for
allowedVersionsspecifically: if a value fails all four parse branches,lookup/filter.tsthrowsCONFIG_VALIDATIONfor the entire repository config, not just the one dependency — so a single bad rule in the shared preset breaks Renovate for every consumer, not just the dep it targets.Suggested addition to the Lint job:
Raised during review of #3791 and kept out of that PR because it modifies CI.