Skip to content

CI: no Renovate config validation gate on a preset that ships org-wide #3793

Description

@marcusrbrown

default.json is a public preset consumed by every repo extending local>fro-bot/.github, but .github/workflows/main.yaml has no Renovate config validation step. A malformed rule ships org-wide with local validation as the only check.

This is not hypothetical for allowedVersions specifically: if a value fails all four parse branches, lookup/filter.ts throws CONFIG_VALIDATION for the entire repository config, not just the one dependency — so a single bad rule in the shared preset breaks Renovate for every consumer, not just the dep it targets.

Suggested addition to the Lint job:

- name: ✅ Validate Renovate config
  run: pnpm dlx --package renovate renovate-config-validator --strict default.json .github/renovate.json5

Raised during review of #3791 and kept out of that PR because it modifies CI.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions