Conversation
Same shape as docsy#2821, minus the audit test: JSONC keeps the comments that configMigration drops from JSON5; actions looked up as GitHub Releases, each bump its own SHA-named PR outside the patch and minor groups. CONTRIBUTING points at Docsy's maintainer notes for the family settings and keeps only this repo's own.
✅ Deploy Preview for goldydocs ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
- Drops the inventory that followed the link and the Releases sentence: Docsy's notes own both (r1.1, r1.3) - Adds the local facts the old text implied: no min-release-age in .npmrc, so the notes' urgent-fix override does not apply here; review guards the pin comments (r1.2)
… had no reason to add
…o ambiguities resolved - Drops the hugo-extended config comment: it gave a reason the docs don't (r2 p1.1); the bullet now states the version-coupled approval, the reason Update Hugo owns (p2.1) - Names Docsy as the override's owner and the PR reviewer as the pin comments' check (p1.2, p2.2)
- Drops the hugo-extended bullet: docsy has the same rule and Docsy's notes and this file's Update Hugo already give the reason - Bootstrap/FA bullet reduced to what differs here: the regenerated manifest and the close-and-route step
… gap to close, not a setting to document
- Adds the npm release cooldown and the install-time script default-deny that docsy added in #2757/#2760, three days after docsy#487 copied the older file; the registry pin stays docsy's (publisher-only) - Pins Node to docsy's version: lts/* floated in CI and was invisible to Renovate's nvm manager
The linked page owns the rationale but names no npm keys; each comment now maps its key to the page's decision name and says nothing the page already does. The Windows shell note stays: a portability fact the page doesn't own.
Each key's name states its effect and the header's link owns the rationale; the Windows shell note stays, the one why the screen can't supply.
… this repo's shape - Names the hugo-extended exclusion's reason (the pin follows Docsy's) and the npm cooldown's local override: update:hugo takes no version, so Docsy's recipe doesn't port (r3.2, r3.3) - netlify.toml's fallback comment names the control that acts, ignore-scripts (r3.4) - "family settings" was our jargon; install:safe is distinguished by lock-exactness only now; dashes constructs reworked (r3.5, r3.6, r3.9, r3.10)
… that runs them ignore-scripts=true would have made CI's npm ci script-free, so an unapproved hugo-extended bump would pass; docsy pays for the key with a targeted rebuild step this repo doesn't have. The strict allowlist on CI's install is the example's gate; netlify.toml's fallback comment is true again.
The next reader diffing this file against docsy's sees a gap and no reason; the comment is the reason, at the point of decision.
…as; .npmrc points there The flow's shape and rationale were the same as Docsy's and restated; what differs (no version argument, no audit or rebuild step, the gate on CI's install) is now the section, and the ignore-scripts absence has its reason there rather than in the config.
… Hugo down to its three differences Docsy's notes own the exclusion, the self-installing binary, the rebuild step and the CI-fails-until-approved consequence; what stayed is what only this repo can say.
The script defaulted to @latest, the opposite of Docsy's reviewed-exact-version step; the maintainer's bump is intentional and pinned, so the command with X.Y.Z is the step, and the doc names it without quoting Docsy's own command.
npm exports unknown run flags as npm_config_*; the flag name avoids npm's own option namespace (--v is npm's version flag). Bash-only expansion, true on every platform through the committed script-shell. The reviewed-version discipline stays where it is enforced: approve:hugo.
- update:hugo out for good: npm 11.19 warns that unknown run flags stop working in the next major, and the unquoted expansion was an argument-injection point; the bump is the pinned command (r4.1) - approve:hugo runs install:safe first: approve-scripts needs a tree and the manifest regeneration reads it, so a fresh checkout of a bump PR now works (r4.2) - CONTRIBUTING: a consumer's plain npm install runs scripts too, so the gate sentence names CI without "the one"; the Renovate opener was Docsy's sentence; two repeats cut (r4.3-r4.5)
…'s two exceptions get their own section The approval gate's purpose (a maintainer has approved every hugo-extended version whose installer may run) was missing; the mechanics had crowded it out. The harmonizer's question (why no ignore-scripts) now has its own home, which the .npmrc pointer targets.
…the maintainer needs the consequence
- timezone was a vestige of docsy's one-day phrase schedule (docsy#2742), copied by docsy#492 the day docsy#2747 dropped it; the cron runs in UTC like every family repo's, and the comment says so - Install configuration: the registry-pin line states this repo's delta; a plain npm install runs hugo-extended's installer and needs network (the consumer-facing consequence of keeping scripts on) - Lockfile and Update Hugo: a dangling "neither install mode" and a front-loaded bump line (r5 prose)
…own override said; approve pins by version - timezone: UTC explicit: unset, Renovate evaluates the cron in the host's zone, so "Sunday (UTC)" was only true on a UTC host (r6.1) - Update Hugo: the pin tracks Docsy's officially supported version (the delta a dropped bullet had left homeless); a bump under the cooldown takes the env override on the install command; approve:hugo's bullet keeps its deltas and points at the manifest section (r6.2, r6.3) - approve:hugo passes --allow-scripts-pin so a user-level allow-scripts-pin=false cannot write a name-level allow (r6.5) - Install configuration: the counterfactual reads as one (r6.4); two colons fixed; Upgrade Docsy linked
… comment claims fixed - The approval covers the install script only and CI flags, not blocks: the bin wrapper runs the same installer at first use, and check-links is not a required check (r7.1) - The Renovate-exclusion clause was Docsy's; the live bot path, a Dependabot security bump, is the delta (r7.2) - Cooldown override by pointer to Docsy's, with the whole-days rule; Docsy's rebuild mechanism by pointer; the third "install:safe runs no scripts" cut (r7.6, r7.7) - engine-strict gets its one why back; the ignore-scripts pointer stands in its own block; the timezone comment names Renovate's docs and code (r7.4, r7.5)
…maintainer's order - The policy names what the example follows and what to do with a Dependabot bump; the command reads as an instruction, the missing script as its trailing why (owner's wording pass) - renovate.jsonc: schedule first, the UTC pin as its rider (owner's edit)
…s); the heading carries the object
…en its three parts as sub-bullets; a dangling link reference removed with the restated pointer
…t restated their keys - The override clause inverted Docsy's guidance (smallest relaxation that admits the release); the pointer alone is right (r8.1) - The repeated "fails npm ci" sentence cut; the flow sentence links Docsy's section again (r8.2, r8.3) - .npmrc: the engine-strict comment misfiled the floor's reason on the strict key (an install the floor refuses ignores nothing); renovate.jsonc: "// Sunday" translated the cron - Link definitions back in alphabetical order
chalin
force-pushed
the
chalin-m24-renovate-alignment-example-2026-0924
branch
from
September 26, 2026 12:23
aa77a8c to
399b5b4
Compare
…longs with the family's schedule guidance
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
renovate.json5→renovate.jsonc(feat(config-migration): preserve comments when migratingrenovate.jsonrenovatebot/renovate#38646)timezonepinned to UTCCONTRIBUTING.mda delta doc: its Docsy-overlapping sections point at Docsy's notes and keep only what differs hereignore-scripts=trueis deliberately not copied, since it would silence the check here (§ Install configuration);approve:hugoworks from a fresh checkout under any user config; manual Hugo updates name a reviewed versionCONTRIBUTING.mdnames the PR reviewer as the checkrenovate.jsoncand.npmrc(no explicittimezone): follow-ups on the Docsy sidedocsyorg: owner step after this landsnpm ciwith scripts on and the hugo-extended approval wrong fails