Renovate opens bump PRs for new Upstream Versions #8

Closed
opened 2026-09-30 13:14:53 +00:00 by piscis · 1 comment
Owner

What to build

Renovate, not a custom workflow, opens the bump PRs (decided in the grilling on #5). renovatebot already runs in the org and opened onboarding PR #13 here; build on it (merge or supersede it).

In this repo's renovate.json:

  • A custom regex manager for pin.env using the git-tags datasource against the canonical Upstream (https://git.b4mad.industries/agentic-forges/forgejo-mcp, ADR 0002). It updates UPSTREAM_VERSION and, as the digest, UPSTREAM_COMMIT together.
  • No postUpgradeTasks. Renovate doesn't touch REBUILD or REBUILD_OF: after a bump, REBUILD_OF no longer matches UPSTREAM_VERSION, so the Rebuild counts as 1 (#16, ADR 0003).
  • "enabled": true: the self-hosted bot skips repos without it (see vicoli/forgejo-renovate-bot's README).
  • Only stable semver tags (ignore pre-releases). The PR description links the Upstream release or changelog.

PRs opened by renovatebot use its own token, so they trigger the PR CI (#6).

Acceptance criteria

  • With the Pin one version behind, Renovate opens exactly one bump PR with the correct version and commit, and the build tags it as Rebuild 1
  • The bump PR triggers the PR CI (build and smoke test), and the Dockerfile's commit check passes
  • While that PR is open, Renovate updates it rather than opening a duplicate
  • With the Pin already at the newest Upstream Version, Renovate does nothing
  • Pre-release tags are ignored

Blocked by

Context: see GLOSSARY.md (Upstream, Upstream Version, Image, Rebuild, Consumer, Pin) and docs/adr/ (0001 build from Upstream source for multi-arch, 0002 canonical Upstream not the Codeberg mirror, 0003 tag scheme and immutable Rebuild tags, 0004 public org vicoli-oss).

## What to build Renovate, not a custom workflow, opens the bump PRs (decided in the grilling on #5). `renovatebot` already runs in the org and opened onboarding PR #13 here; build on it (merge or supersede it). In this repo's `renovate.json`: - A **custom regex manager** for `pin.env` using the `git-tags` datasource against the canonical Upstream (`https://git.b4mad.industries/agentic-forges/forgejo-mcp`, ADR 0002). It updates `UPSTREAM_VERSION` and, as the digest, `UPSTREAM_COMMIT` together. - **No `postUpgradeTasks`.** Renovate doesn't touch `REBUILD` or `REBUILD_OF`: after a bump, `REBUILD_OF` no longer matches `UPSTREAM_VERSION`, so the Rebuild counts as 1 (#16, ADR 0003). - `"enabled": true`: the self-hosted bot skips repos without it (see `vicoli/forgejo-renovate-bot`'s README). - Only stable semver tags (ignore pre-releases). The PR description links the Upstream release or changelog. PRs opened by `renovatebot` use its own token, so they trigger the PR CI (#6). ## Acceptance criteria - [ ] With the Pin one version behind, Renovate opens exactly one bump PR with the correct version and commit, and the build tags it as Rebuild `1` - [ ] The bump PR triggers the PR CI (build and smoke test), and the Dockerfile's commit check passes - [ ] While that PR is open, Renovate updates it rather than opening a duplicate - [ ] With the Pin already at the newest Upstream Version, Renovate does nothing - [ ] Pre-release tags are ignored ## Blocked by - #6 - #5 - #16 Context: see `GLOSSARY.md` (Upstream, Upstream Version, Image, Rebuild, Consumer, Pin) and `docs/adr/` (0001 build from Upstream source for multi-arch, 0002 canonical Upstream not the Codeberg mirror, 0003 tag scheme and immutable Rebuild tags, 0004 public org `vicoli-oss`).
piscis changed title from Daily workflow opens bump PRs for new Upstream Versions to Renovate opens bump PRs for new Upstream Versions 2026-09-30 13:47:16 +00:00
piscis self-assigned this 2026-09-30 15:24:47 +00:00
Author
Owner

Live bot check, 2026-09-30 (Renovate 43, renovatebot):

  • Pin one version behind → exactly one bump PR. I set the Pin to v3.1.0 on main (c261ae2), and renovatebot opened #29 on renovate/forgejo-mcp. The diff changes only UPSTREAM_VERSION → v3.2.0 and UPSTREAM_COMMIT → e30bb7e2e45c0e447506b5df1fe83ebce4b43944, the commit the tag points to, not the tag object 931a525d. REBUILD/REBUILD_OF are untouched, and make print-tag on the branch gives 3.2.0-r1. The body links the Upstream release and embeds its release notes.
  • The bump PR triggers PR CI, which passed on the bot's own token (ci / build (pull_request) on f2ec6c4e, including the Dockerfile's commit check). I merged #29, which restored the Pin.
  • Pin current → nothing. The bot's next pass (17:07 UTC) deleted the merged branch and opened no new PR. The old renovate/configure branch is gone too, and there's no Dependency Dashboard issue.
  • Pre-releases ignored. allowedVersions blocks them, shown offline in #27. Upstream has had no pre-release tag since, so this is not live-verified.
  • Updates instead of duplicating. Not live-verified: I merged #29 before a second bot run, so the Pin wouldn't sit behind on main. The config ensures it: renovate/forgejo-mcp is the only branch, even across majors.

The bot got stuck at first. It couldn't push to this repo because the vicoli-oss Bots team only had read, and Renovate aborts on repos without push. I raised the team to write, which also raised the releases, wiki and projects units to write.

Live bot check, 2026-09-30 (Renovate 43, `renovatebot`): - [x] **Pin one version behind → exactly one bump PR.** I set the Pin to `v3.1.0` on main (`c261ae2`), and `renovatebot` opened #29 on `renovate/forgejo-mcp`. The diff changes only `UPSTREAM_VERSION` → `v3.2.0` and `UPSTREAM_COMMIT` → `e30bb7e2e45c0e447506b5df1fe83ebce4b43944`, the commit the tag points to, not the tag object `931a525d`. `REBUILD`/`REBUILD_OF` are untouched, and `make print-tag` on the branch gives `3.2.0-r1`. The body links the Upstream release and embeds its release notes. - [x] **The bump PR triggers PR CI**, which passed on the bot's own token (`ci / build (pull_request)` on `f2ec6c4e`, including the Dockerfile's commit check). I merged #29, which restored the Pin. - [x] **Pin current → nothing.** The bot's next pass (17:07 UTC) deleted the merged branch and opened no new PR. The old `renovate/configure` branch is gone too, and there's no Dependency Dashboard issue. - [x] **Pre-releases ignored.** `allowedVersions` blocks them, shown offline in #27. Upstream has had no pre-release tag since, so this is not live-verified. - [ ] **Updates instead of duplicating.** Not live-verified: I merged #29 before a second bot run, so the Pin wouldn't sit behind on main. The config ensures it: `renovate/forgejo-mcp` is the only branch, even across majors. The bot got stuck at first. It couldn't push to this repo because the `vicoli-oss` **Bots** team only had `read`, and Renovate aborts on repos without push. I raised the team to `write`, which also raised the releases, wiki and projects units to write.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference
vicoli-oss/docker-forgejo-mcp#8
No description provided.