Skip to content

chore(renovate): onboard to shared Renovate preset - #38

Merged
Mtze merged 2 commits into
mainfrom
chore/renovate-config
Aug 27, 2026
Merged

Mtze merged 2 commits into
mainfrom
chore/renovate-config

Conversation

@Mtze

@Mtze Mtze commented Aug 27, 2026 •

Copy link
Copy Markdown
Member

What and why

Onboards this repo to the org-wide Renovate rollout, plus two small cleanups that turned up while doing it.

  • Adds renovate.json at the repo root. It is deliberately minimal and just extends the shared preset (local>EduIDE/.github:renovate-config), so update policy stays in one place instead of drifting per repo.
  • Deletes .whitesource, config left over from an abandoned Mend Bolt trial. Nothing else in the repo references it and no Mend check runs on PRs here.
  • Removes the fs dependency from package.json. fs@0.0.1-security is a squatting placeholder on npm, not the Node builtin. Every fs import in this repo is a plain from "fs", which Node resolves to the builtin regardless of what sits in node_modules, so this is a no-op at runtime. The lockfile was regenerated with npm install --package-lock-only.

The shared preset lives in EduIDE/.github#4, which has not merged yet. That is fine: this PR does not depend on it landing first. Renovate resolves the preset when it runs, so it will simply pick it up once #4 is in.

How it was verified

What I actually ran:

  • npx --yes --package renovate@44.46.7 -- renovate-config-validator --strict renovate.json - passes, exit code 0. I sanity-checked the validator by feeding it a config with a bogus option first, and it did report an error, so the pass is meaningful rather than a no-op.
  • npm install --package-lock-only and then inspected git diff package-lock.json. The diff is exactly 7 deleted lines: the fs entry in the root dependencies block and the node_modules/fs package entry. Nothing else in the lockfile moved.
  • grep across all .ts/.js/.mjs files for fs imports. All 21 hits are import fs from "fs" or import { readFileSync } from "fs". There are no require("fs/...")-style or deep-path imports that could have resolved into the placeholder package.

Explicitly not verified:

  • The test suites were not run locally. node_modules is not installed in my working tree (I only ran --package-lock-only, per instructions), and the Playwright suites need self-hosted runners plus Keycloak/Artemis credentials. The pull_request runs of functional-tests.yml and artemis-integration-tests.yml on this PR are the real check.
  • The preset itself is not resolved by renovate-config-validator; it validates schema and syntax only. That the preset path points at a file that exists cannot be confirmed until chore(renovate): add org-wide shared Renovate config .github#4 merges.

Deployment impact

  • None. No runtime, build, or CI configuration changes.

Risk and rollback

Low. Nothing here is on an execution path.

The only change with any theoretical bite is dropping fs, and that is inert: Node's resolver always prefers the builtin fs over a same-named package in node_modules, so no import site changes meaning. If something unexpected does break, revert this commit and run npm install --package-lock-only to restore the entry.

renovate.json has no effect at all until Renovate is enabled on the repo. Rollback is deleting the file.

Follow-up

A dependency-review check will be wired up separately once EduIDE/.github#4 lands. No CI changes in this PR.

Summary by CodeRabbit

  • Chores
    • Updated dependency management configuration.
    • Added automated update settings based on the shared project configuration.
    • Removed an unused package dependency.
    • Removed legacy dependency-scanning configuration.

Adds a minimal renovate.json extending the org-wide shared preset in
EduIDE/.github, so dependency update policy is maintained in one place
rather than per repo.

Also cleans up two leftovers found while doing this:

- Deletes .whitesource, config for an abandoned Mend Bolt trial. Nothing
  else in the repo references it and no Mend check runs on PRs.
- Drops the "fs" dependency. That is a squatting placeholder package on
  npm, not the Node builtin. Every import in this repo uses `import ...
  from "fs"`, which Node resolves to the builtin regardless of what sits
  in node_modules, so removing it changes no behaviour.

The lockfile was regenerated with `npm install --package-lock-only`; the
resulting diff is limited to dropping the "fs" entry.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QLGHEpzx7D9NYHx4fCmHa9
@coderabbitai

coderabbitai Bot commented Aug 27, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

Next included review available in 54 minutes.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 1ae304bb-354a-4743-85ac-3d2d9657a7ba

📥 Commits

Reviewing files that changed from the base of the PR and between f162d6f and d50e5b3.

📒 Files selected for processing (1)
  • .github/workflows/artillery-tests.yml

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: e9925085-3f28-44e3-869a-21771f9634e1

📥 Commits

Reviewing files that changed from the base of the PR and between 1528a08 and f162d6f.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (3)
  • .whitesource
  • package.json
  • renovate.json
💤 Files with no reviewable changes (2)
  • package.json
  • .whitesource

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The PR removes the Mend configuration and the fs dependency. It adds a Renovate configuration that uses the shared EduIDE/.github preset.

Changes

Repository maintenance

Layer / File(s) Summary
Dependency and update configuration
.whitesource, package.json, renovate.json
The Mend configuration is removed. The fs dependency is removed while fs-extra remains. Renovate now uses its schema and the shared local>EduIDE/.github:renovate-config preset.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Merge Risk: ⚪ Minimal · up to f162d

This PR adds the shared Renovate configuration, removes obsolete metadata, and drops an unused placeholder dependency without changing runtime behavior. No actionable merge-blocking risk remains beyond normal checks and review.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: onboarding the repository to the shared Renovate preset. It matches the added renovate.json configuration.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.)

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/renovate-config

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

The Artillery job has been red since its last green run in May. It is not
a test failure: `npx playwright install --with-deps` runs `apt-get update`,
and packages.microsoft.com now returns 403 for the azure-cli and prod
repos, which aborts apt with exit 100 before any browser is downloaded.

Nothing in this repo needs those Microsoft repos, and the hosted runner
image already ships the Playwright system libraries. Removing the two
source lists lets apt succeed. Also narrows the install to chromium - the
load test only drives chromium, so pulling firefox and webkit was wasted
time on every run.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QLGHEpzx7D9NYHx4fCmHa9
@Mtze
Mtze merged commit 029fba7 into main Aug 27, 2026
4 of 7 checks passed
Mtze added a commit that referenced this pull request Aug 28, 2026
…#39)

#38 fixed the first of two things wrong with this job - apt failing on an
unreachable Microsoft mirror - and that is now on main. With that out of
the way the job gets one step further and hits the second: the container
behind artilleryio/action-cli@v1 no longer has a working entrypoint, so
the step dies with `/home/node/artillery/bin/run: not found` before the
scenario starts.

artillery ^2.0.24 is already a devDependency and npm ci has run by this
point, so npx artillery run does the same work without the container.

The job has been red since May; neither failure is a test failure.


Claude-Session: https://claude.ai/code/session_01QLGHEpzx7D9NYHx4fCmHa9

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant