Skip to content

Track pinned Python deps in workflows via Renovate - #23511

Merged
AAraKKe merged 2 commits into
masterfrom
aarakke/renovate-workflow-deps
Apr 29, 2026
Merged

AAraKKe merged 2 commits into
masterfrom
aarakke/renovate-workflow-deps

Conversation

@AAraKKe

@AAraKKe AAraKKe commented Apr 29, 2026 •

Copy link
Copy Markdown
Collaborator

What does this PR do?

Adds a custom regex manager to renovate.json so Renovate proposes bumps for name==X.Y[.Z] pins inside .github/workflows/*.yml. The existing github-actions manager doesn't see pip dependencies installed in workflow run: steps, so those pins drift silently today.

All proposed PRs require human review (no auto-merge). Grouped under a single weekly batch with the renovate/workflow-deps label.

Motivation

We pinned hatch and virtualenv in build-ddev.yml for deterministic builds and stable cache reuse, and we want a mechanism that keeps those pins (and any future ones) up to date without manual tracking.

Review checklist (to be filled by reviewers)

  • Feature or bugfix MUST have appropriate tests (unit, integration, e2e)
  • Add the `qa/skip-qa` label if the PR doesn't need to be tested during QA.
  • If you need to backport this PR to another branch, you can add the `backport/` label to the PR and it will automatically open a backport PR once this one is merged

Add a custom regex manager that picks up 'name==X.Y[.Z]' patterns in
.github/workflows/*.yml and proposes Renovate PRs to bump them. Groups
all workflow Python deps under one weekly batch with a dedicated label.
PRs require human review (no auto-merge).
@AAraKKe
AAraKKe requested a review from a team as a code owner April 29, 2026 09:48
@AAraKKe AAraKKe added the qa/skip-qa Automatically skip this PR for the next QA label Apr 29, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 04411e7ca6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread renovate.json Outdated
"^\\.github/workflows/[^/]+\\.ya?ml$"
],
"matchStrings": [
"(?<depName>[a-zA-Z][a-zA-Z0-9._-]*)==(?<currentValue>[0-9]+(?:\\.[0-9]+){1,2})"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Match pins stored behind workflow expressions

With the workflows in this commit, this pattern only detects literal package==1.2.3 strings; it misses the PYOXIDIZER_VERSION: "0.24.0" value used by pyoxidizer==${{ env.PYOXIDIZER_VERSION }} in build-ddev.yml and the default ddev fallback in release-dispatch.yml where the version appears after || '==14.3.2'. I checked the configured regex against the top-level workflow YAMLs and it only matches pytest==8.3.5, so the new manager silently leaves two of the intended pinned workflow dependencies untracked.

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Covered with an annotation on env variables where we define versions

Codex review on PR #23511 noted that the regex manager only matches
literal name==X.Y.Z pins, missing two of the four pinned workflow
deps (pyoxidizer via the PYOXIDIZER_VERSION env var, and the ddev
fallback default in release-dispatch.yml).

- Annotate PYOXIDIZER_VERSION with '# renovate: datasource=pypi
  depName=pyoxidizer'.
- Refactor release-dispatch.yml to extract the default ddev version
  into a DEFAULT_DDEV_VERSION env var with the same annotation. The
  resolved install command is functionally equivalent.
- Extend renovate.json's customManager with a second matchString
  pattern that picks up annotated 'KEY: "X.Y[.Z]"' env values.
- Add validate-renovate-config.yml so CI fails if renovate.json ever
  becomes invalid.
@dd-octo-sts

dd-octo-sts Bot commented Apr 29, 2026

Copy link
Copy Markdown
Contributor

Validation Report

All 20 validations passed.

Show details
Validation Description Status
agent-reqs Verify check versions match the Agent requirements file ✅
ci Validate CI configuration and Codecov settings ✅
codeowners Validate every integration has a CODEOWNERS entry ✅
config Validate default configuration files against spec.yaml ✅
dep Verify dependency pins are consistent and Agent-compatible ✅
http Validate integrations use the HTTP wrapper correctly ✅
imports Validate check imports do not use deprecated modules ✅
integration-style Validate check code style conventions ✅
jmx-metrics Validate JMX metrics definition files and config ✅
labeler Validate PR labeler config matches integration directories ✅
legacy-signature Validate no integration uses the legacy Agent check signature ✅
license-headers Validate Python files have proper license headers ✅
licenses Validate third-party license attribution list ✅
metadata Validate metadata.csv metric definitions ✅
models Validate configuration data models match spec.yaml ✅
openmetrics Validate OpenMetrics integrations disable the metric limit ✅
package Validate Python package metadata and naming ✅
readmes Validate README files have required sections ✅
saved-views Validate saved view JSON file structure and fields ✅
version Validate version consistency between package and changelog ✅

View full run

@NouemanKHAL NouemanKHAL left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice, that wast fast! 🚀

@AAraKKe
AAraKKe added this pull request to the merge queue Apr 29, 2026
Merged via the queue into master with commit 055dc82 Apr 29, 2026
49 of 51 checks passed
@AAraKKe
AAraKKe deleted the aarakke/renovate-workflow-deps branch April 29, 2026 12:22
@dd-octo-sts dd-octo-sts Bot added this to the 7.79.0 milestone Apr 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants