Repository navigation
Track pinned Python deps in workflows via Renovate - #23511
Conversation
Add a custom regex manager that picks up 'name==X.Y[.Z]' patterns in .github/workflows/*.yml and proposes Renovate PRs to bump them. Groups all workflow Python deps under one weekly batch with a dedicated label. PRs require human review (no auto-merge).
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 04411e7ca6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| "^\\.github/workflows/[^/]+\\.ya?ml$" | ||
| ], | ||
| "matchStrings": [ | ||
| "(?<depName>[a-zA-Z][a-zA-Z0-9._-]*)==(?<currentValue>[0-9]+(?:\\.[0-9]+){1,2})" |
There was a problem hiding this comment.
Match pins stored behind workflow expressions
With the workflows in this commit, this pattern only detects literal package==1.2.3 strings; it misses the PYOXIDIZER_VERSION: "0.24.0" value used by pyoxidizer==${{ env.PYOXIDIZER_VERSION }} in build-ddev.yml and the default ddev fallback in release-dispatch.yml where the version appears after || '==14.3.2'. I checked the configured regex against the top-level workflow YAMLs and it only matches pytest==8.3.5, so the new manager silently leaves two of the intended pinned workflow dependencies untracked.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Covered with an annotation on env variables where we define versions
Codex review on PR #23511 noted that the regex manager only matches literal name==X.Y.Z pins, missing two of the four pinned workflow deps (pyoxidizer via the PYOXIDIZER_VERSION env var, and the ddev fallback default in release-dispatch.yml). - Annotate PYOXIDIZER_VERSION with '# renovate: datasource=pypi depName=pyoxidizer'. - Refactor release-dispatch.yml to extract the default ddev version into a DEFAULT_DDEV_VERSION env var with the same annotation. The resolved install command is functionally equivalent. - Extend renovate.json's customManager with a second matchString pattern that picks up annotated 'KEY: "X.Y[.Z]"' env values. - Add validate-renovate-config.yml so CI fails if renovate.json ever becomes invalid.
Validation ReportAll 20 validations passed. Show details
|
What does this PR do?
Adds a custom regex manager to
renovate.jsonso Renovate proposes bumps forname==X.Y[.Z]pins inside.github/workflows/*.yml. The existinggithub-actionsmanager doesn't see pip dependencies installed in workflowrun:steps, so those pins drift silently today.All proposed PRs require human review (no auto-merge). Grouped under a single weekly batch with the
renovate/workflow-depslabel.Motivation
We pinned
hatchandvirtualenvinbuild-ddev.ymlfor deterministic builds and stable cache reuse, and we want a mechanism that keeps those pins (and any future ones) up to date without manual tracking.Review checklist (to be filled by reviewers)