Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
💤 Files with no reviewable changes (1)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review. 📝 WalkthroughWalkthroughThe pull request removes the Dependabot configuration and adds Renovate configuration for GitHub Actions and Go modules. The new settings define update timing, post-update behavior, labels, package grouping, excluded dependency types, and digest-pinning rules. ChangesDependency update configuration
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~8 minutes Change: Other Merge Risk: ⚪ Minimal · up to This changes dependency updates to Renovate while preserving the existing GitHub Actions and Go module coverage. Grant the Renovate app repository access after merging; no identified issue otherwise blocks merging. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This moves the dependency updates of this repository from Dependabot to Renovate, which already handles this for core, frontend, android and several other Home Assistant repositories. It adds
.github/renovate.jsonand removes.github/dependabot.yml.go mod tidyafter each update sogo.modandgo.sumstay clean, and thegolabel Dependabot applied.golang.org/x/*modules are grouped. They are released together every month, and came in as separate PRs so far (golang.org/x/termalone eight times this year).go.modis left alone. Moving to a new Go release is a deliberate change, together withGOLANG_VERSIONin the workflows.github_actionslabel. Actions are pinned to commit SHAs (with the version as a comment) throughhelpers:pinGitHubActionDigests, and kept up to date that way. Our own actions that follow a branch, likehome-assistant/actions@master, keep floating; pinning those would mean a digest PR in every repository for every change to them. Runner labels and action version inputs are left alone, as Dependabot never updated those.Tested with a local Renovate run (
--platform=local --dry-run=full). The Go modules are all up to date, so once active, expect two PRs: a "Pin dependencies" PR that pins the actions (checkout, setup-go, golangci-lint, release-drafter and codespell), and an update ofcodespell-project/actions-codespellfrom v2.2 to v2.4.3. It was on the floatingv2.2tag, which Dependabot never updated. Also validated withrenovate-config-validator --strict.Summary by CodeRabbit