Skip to content

Align Renovate and toolchain settings with Docsy - #511

Draft
chalin wants to merge 28 commits into
docsy:mainfrom
chalin:chalin-m24-renovate-alignment-example-2026-0924
Draft

chalin wants to merge 28 commits into
docsy:mainfrom
chalin:chalin-m24-renovate-alignment-example-2026-0924

Conversation

@chalin

@chalin chalin commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator
  • Scope: docsy-example's Renovate config at Renovate: move config to JSONC, harden GitHub Actions bumps docsy#2821's shape, with its npm and Node config back in step with Docsy
  • Out of scope:
    • a pin-comment audit test like Docsy's: this repo has no supply-chain audit; CONTRIBUTING.md names the PR reviewer as the check
    • Docsy's own renovate.jsonc and .npmrc (no explicit timezone): follow-ups on the Docsy side
    • enabling the Renovate app on the docsy org: owner step after this lands
    • dependency bumps of any kind; the pending ones arrive as Renovate PRs
  • Verified (renovate 44.82.5, npm 11.19.0, empty user config):
    • passes the strict config validator
    • proves the approval check red-first: a CI-shaped npm ci with scripts on and the hugo-extended approval wrong fails

Same shape as docsy#2821, minus the audit test: JSONC keeps the comments that configMigration drops from JSON5; actions looked up as GitHub Releases, each bump its own SHA-named PR outside the patch and minor groups. CONTRIBUTING points at Docsy's maintainer notes for the family settings and keeps only this repo's own.
@chalin chalin added the CI/infra CI & infrastructure label Sep 24, 2026
@netlify

netlify Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for goldydocs ready!

Name Link
🔨 Latest commit 21a778b
🔍 Latest deploy log https://app.netlify.com/projects/goldydocs/deploys/6ab7c2631607f3000882393a
😎 Deploy Preview https://deploy-preview-511--goldydocs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

- Drops the inventory that followed the link and the Releases sentence: Docsy's notes own both (r1.1, r1.3)
- Adds the local facts the old text implied: no min-release-age in .npmrc, so the notes' urgent-fix override does not apply here; review guards the pin comments (r1.2)
…o ambiguities resolved

- Drops the hugo-extended config comment: it gave a reason the docs don't (r2 p1.1); the bullet now states the version-coupled approval, the reason Update Hugo owns (p2.1)
- Names Docsy as the override's owner and the PR reviewer as the pin comments' check (p1.2, p2.2)
- Drops the hugo-extended bullet: docsy has the same rule and Docsy's notes and this file's Update Hugo already give the reason
- Bootstrap/FA bullet reduced to what differs here: the regenerated manifest and the close-and-route step
- Adds the npm release cooldown and the install-time script default-deny that docsy added in #2757/#2760, three days after docsy#487 copied the older file; the registry pin stays docsy's (publisher-only)
- Pins Node to docsy's version: lts/* floated in CI and was invisible to Renovate's nvm manager
The linked page owns the rationale but names no npm keys; each comment now maps its key to the page's decision name and says nothing the page already does. The Windows shell note stays: a portability fact the page doesn't own.
Each key's name states its effect and the header's link owns the rationale; the Windows shell note stays, the one why the screen can't supply.
… this repo's shape

- Names the hugo-extended exclusion's reason (the pin follows Docsy's) and the npm cooldown's local override: update:hugo takes no version, so Docsy's recipe doesn't port (r3.2, r3.3)
- netlify.toml's fallback comment names the control that acts, ignore-scripts (r3.4)
- "family settings" was our jargon; install:safe is distinguished by lock-exactness only now; dashes constructs reworked (r3.5, r3.6, r3.9, r3.10)
@chalin chalin changed the title Renovate: move config to JSONC, harden GitHub Actions bumps Renovate: move config to JSONC, harden GitHub Actions bumps; npm and Node config back in step with docsy Sep 25, 2026
… that runs them

ignore-scripts=true would have made CI's npm ci script-free, so an unapproved hugo-extended bump would pass; docsy pays for the key with a targeted rebuild step this repo doesn't have. The strict allowlist on CI's install is the example's gate; netlify.toml's fallback comment is true again.
The next reader diffing this file against docsy's sees a gap and no reason; the comment is the reason, at the point of decision.
…as; .npmrc points there

The flow's shape and rationale were the same as Docsy's and restated; what differs (no version argument, no audit or rebuild step, the gate on CI's install) is now the section, and the ignore-scripts absence has its reason there rather than in the config.
… Hugo down to its three differences

Docsy's notes own the exclusion, the self-installing binary, the rebuild step and the CI-fails-until-approved consequence; what stayed is what only this repo can say.
The script defaulted to @latest, the opposite of Docsy's reviewed-exact-version step; the maintainer's bump is intentional and pinned, so the command with X.Y.Z is the step, and the doc names it without quoting Docsy's own command.
npm exports unknown run flags as npm_config_*; the flag name avoids npm's own option namespace (--v is npm's version flag). Bash-only expansion, true on every platform through the committed script-shell. The reviewed-version discipline stays where it is enforced: approve:hugo.
- update:hugo out for good: npm 11.19 warns that unknown run flags stop working in the next major, and the unquoted expansion was an argument-injection point; the bump is the pinned command (r4.1)
- approve:hugo runs install:safe first: approve-scripts needs a tree and the manifest regeneration reads it, so a fresh checkout of a bump PR now works (r4.2)
- CONTRIBUTING: a consumer's plain npm install runs scripts too, so the gate sentence names CI without "the one"; the Renovate opener was Docsy's sentence; two repeats cut (r4.3-r4.5)
@chalin chalin changed the title Renovate: move config to JSONC, harden GitHub Actions bumps; npm and Node config back in step with docsy Align Renovate and toolchain settings with Docsy Sep 25, 2026
…'s two exceptions get their own section

The approval gate's purpose (a maintainer has approved every hugo-extended version whose installer may run) was missing; the mechanics had crowded it out. The harmonizer's question (why no ignore-scripts) now has its own home, which the .npmrc pointer targets.
- timezone was a vestige of docsy's one-day phrase schedule (docsy#2742), copied by docsy#492 the day docsy#2747 dropped it; the cron runs in UTC like every family repo's, and the comment says so
- Install configuration: the registry-pin line states this repo's delta; a plain npm install runs hugo-extended's installer and needs network (the consumer-facing consequence of keeping scripts on)
- Lockfile and Update Hugo: a dangling "neither install mode" and a front-loaded bump line (r5 prose)
…own override said; approve pins by version

- timezone: UTC explicit: unset, Renovate evaluates the cron in the host's zone, so "Sunday (UTC)" was only true on a UTC host (r6.1)
- Update Hugo: the pin tracks Docsy's officially supported version (the delta a dropped bullet had left homeless); a bump under the cooldown takes the env override on the install command; approve:hugo's bullet keeps its deltas and points at the manifest section (r6.2, r6.3)
- approve:hugo passes --allow-scripts-pin so a user-level allow-scripts-pin=false cannot write a name-level allow (r6.5)
- Install configuration: the counterfactual reads as one (r6.4); two colons fixed; Upgrade Docsy linked
… comment claims fixed

- The approval covers the install script only and CI flags, not blocks: the bin wrapper runs the same installer at first use, and check-links is not a required check (r7.1)
- The Renovate-exclusion clause was Docsy's; the live bot path, a Dependabot security bump, is the delta (r7.2)
- Cooldown override by pointer to Docsy's, with the whole-days rule; Docsy's rebuild mechanism by pointer; the third "install:safe runs no scripts" cut (r7.6, r7.7)
- engine-strict gets its one why back; the ignore-scripts pointer stands in its own block; the timezone comment names Renovate's docs and code (r7.4, r7.5)
…maintainer's order

- The policy names what the example follows and what to do with a Dependabot bump; the command reads as an instruction, the missing script as its trailing why (owner's wording pass)
- renovate.jsonc: schedule first, the UTC pin as its rider (owner's edit)
…en its three parts as sub-bullets; a dangling link reference removed with the restated pointer
…t restated their keys

- The override clause inverted Docsy's guidance (smallest relaxation that admits the release); the pointer alone is right (r8.1)
- The repeated "fails npm ci" sentence cut; the flow sentence links Docsy's section again (r8.2, r8.3)
- .npmrc: the engine-strict comment misfiled the floor's reason on the strict key (an install the floor refuses ignores nothing); renovate.jsonc: "// Sunday" translated the cron
- Link definitions back in alphabetical order
@chalin
chalin force-pushed the chalin-m24-renovate-alignment-example-2026-0924 branch from aa77a8c to 399b5b4 Compare September 26, 2026 12:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CI/infra CI & infrastructure

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant