From bdeca14a827a92c204c8a0fd4e5571e6dba3a97c Mon Sep 17 00:00:00 2001 From: Matthias Linhuber Date: Thu, 27 Aug 2026 17:18:47 +0200 Subject: [PATCH 1/2] chore(renovate): onboard to the org-wide shared preset Extends local>EduIDE/.github:renovate-config, plus two repo-specific rules this repo needs on top of the shared policy: - Disable everything under demo/dockerfiles/demo-theia-docker/project/. That tree is the sample workspace baked into the demo image for users to open in the IDE (com.example:demo with junit 4.13.2, and a web-example package.json). It is content, not a dependency of this repo, and bumping it would change what the demo shows without fixing anything. - Pin terraform providers to rangeStrategy "replace". All 13 versions.tf files use unbounded ">=" constraints, which "auto" would leave untouched forever. "replace" moves the floor only when it genuinely moves. The shared preset already disables -SNAPSHOT versions and the org.eclipse.theia.cloud:* Maven coordinates, so the reactor modules at 1.2.0-SNAPSHOT need no rule here. Also drops the orphan root package-lock.json. There is no package.json at the repo root, and the lockfile pinned only crypto-js, which nothing in the repo references. Renovate's npm manager keys off package.json, so the file was already inert - it only misleads humans. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01QLGHEpzx7D9NYHx4fCmHa9 --- package-lock.json | 18 ------------------ renovate.json | 17 +++++++++++++++++ 2 files changed, 17 insertions(+), 18 deletions(-) delete mode 100644 package-lock.json create mode 100644 renovate.json diff --git a/package-lock.json b/package-lock.json deleted file mode 100644 index 8fd788abb..000000000 --- a/package-lock.json +++ /dev/null @@ -1,18 +0,0 @@ -{ - "name": "theia-cloud", - "lockfileVersion": 3, - "requires": true, - "packages": { - "": { - "dependencies": { - "crypto-js": "^4.2.0" - } - }, - "node_modules/crypto-js": { - "version": "4.2.0", - "resolved": "https://registry.npmjs.org/crypto-js/-/crypto-js-4.2.0.tgz", - "integrity": "sha512-KALDyEYgpY+Rlob/iriUtjV6d5Eq+Y191A5g4UqLAi8CyGP9N1+FdVbkc1SxKc2r4YAYqG8JzO2KGL+AizD70Q==", - "license": "MIT" - } - } -} diff --git a/renovate.json b/renovate.json new file mode 100644 index 000000000..ae6f78df6 --- /dev/null +++ b/renovate.json @@ -0,0 +1,17 @@ +{ + "$schema": "https://docs.renovatebot.com/renovate-schema.json", + "extends": ["local>EduIDE/.github:renovate-config"], + "packageRules": [ + { + "description": "Sample project shipped for the demo, not a dependency of this repo.", + "matchFileNames": ["demo/dockerfiles/demo-theia-docker/project/**"], + "enabled": false + }, + { + "description": "Terraform providers use unbounded >= constraints; only surface a PR when the floor genuinely moves.", + "matchManagers": ["terraform"], + "matchDepTypes": ["provider", "required_provider"], + "rangeStrategy": "replace" + } + ] +} From 3f5170c7b6405fae65d626ebd71be3636c6c80b8 Mon Sep 17 00:00:00 2001 From: Matthias Linhuber Date: Thu, 27 Aug 2026 17:20:42 +0200 Subject: [PATCH 2/2] fix(ci): stop skipping the service test suite in the image build org.eclipse.theia.cloud.service has 12 test classes (~2100 LOC) covering the auth filters, session and workspace resources, K8sUtil and the anonymous identity provider. None of them have been running: the service image build passes -Dmaven.test.skip=true, and no other workflow invokes them either. The operator image already builds with `mvn clean verify` and runs its tests, so this brings the service in line rather than inventing a new gate. Dropping the flag is the whole change - surefire then runs during `package` as it normally would. This matters now because dependency updates are about to be automated. Renovate will open Quarkus and Maven bumps against this module, and until this change the only thing standing behind them was "it compiles". Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01QLGHEpzx7D9NYHx4fCmHa9 --- dockerfiles/service/Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/dockerfiles/service/Dockerfile b/dockerfiles/service/Dockerfile index 481da2efd..28c7b8170 100644 --- a/dockerfiles/service/Dockerfile +++ b/dockerfiles/service/Dockerfile @@ -32,7 +32,7 @@ RUN --mount=type=secret,id=SENTRY_AUTH_TOKEN \ cd /service/common/org.eclipse.theia.cloud.common && \ mvn clean install --no-transfer-progress -Drevision=${APP_VERSION} $MAVEN_SENTRY_ARGS && \ cd /service/service/org.eclipse.theia.cloud.service && \ - mvn clean package -Drevision=${APP_VERSION} -Dmaven.test.skip=true -Dquarkus.package.type=uber-jar --no-transfer-progress $MAVEN_SENTRY_ARGS + mvn clean package -Drevision=${APP_VERSION} -Dquarkus.package.type=uber-jar --no-transfer-progress $MAVEN_SENTRY_ARGS FROM eclipse-temurin:21-jre-alpine ARG APP_VERSION=1.2.0-SNAPSHOT