chore(renovate): onboard to shared Renovate preset - #38
Conversation
Adds a minimal renovate.json extending the org-wide shared preset in EduIDE/.github, so dependency update policy is maintained in one place rather than per repo. Also cleans up two leftovers found while doing this: - Deletes .whitesource, config for an abandoned Mend Bolt trial. Nothing else in the repo references it and no Mend check runs on PRs. - Drops the "fs" dependency. That is a squatting placeholder package on npm, not the Node builtin. Every import in this repo uses `import ... from "fs"`, which Node resolves to the builtin regardless of what sits in node_modules, so removing it changes no behaviour. The lockfile was regenerated with `npm install --package-lock-only`; the resulting diff is limited to dropping the "fs" entry. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QLGHEpzx7D9NYHx4fCmHa9
|
Warning Review limit reachedNext included review available in 54 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (3)
💤 Files with no reviewable changes (2)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe PR removes the Mend configuration and the ChangesRepository maintenance
Estimated code review effort: 1 (Trivial) | ~2 minutes Merge Risk: ⚪ Minimal · up to This PR adds the shared Renovate configuration, removes obsolete metadata, and drops an unused placeholder dependency without changing runtime behavior. No actionable merge-blocking risk remains beyond normal checks and review. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Full details: Docstring CoverageExplanation No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.) ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
The Artillery job has been red since its last green run in May. It is not a test failure: `npx playwright install --with-deps` runs `apt-get update`, and packages.microsoft.com now returns 403 for the azure-cli and prod repos, which aborts apt with exit 100 before any browser is downloaded. Nothing in this repo needs those Microsoft repos, and the hosted runner image already ships the Playwright system libraries. Removing the two source lists lets apt succeed. Also narrows the install to chromium - the load test only drives chromium, so pulling firefox and webkit was wasted time on every run. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QLGHEpzx7D9NYHx4fCmHa9
…#39) #38 fixed the first of two things wrong with this job - apt failing on an unreachable Microsoft mirror - and that is now on main. With that out of the way the job gets one step further and hits the second: the container behind artilleryio/action-cli@v1 no longer has a working entrypoint, so the step dies with `/home/node/artillery/bin/run: not found` before the scenario starts. artillery ^2.0.24 is already a devDependency and npm ci has run by this point, so npx artillery run does the same work without the container. The job has been red since May; neither failure is a test failure. Claude-Session: https://claude.ai/code/session_01QLGHEpzx7D9NYHx4fCmHa9 Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
What and why
Onboards this repo to the org-wide Renovate rollout, plus two small cleanups that turned up while doing it.
renovate.jsonat the repo root. It is deliberately minimal and just extends the shared preset (local>EduIDE/.github:renovate-config), so update policy stays in one place instead of drifting per repo..whitesource, config left over from an abandoned Mend Bolt trial. Nothing else in the repo references it and no Mend check runs on PRs here.fsdependency frompackage.json.fs@0.0.1-securityis a squatting placeholder on npm, not the Node builtin. Everyfsimport in this repo is a plainfrom "fs", which Node resolves to the builtin regardless of what sits innode_modules, so this is a no-op at runtime. The lockfile was regenerated withnpm install --package-lock-only.The shared preset lives in EduIDE/.github#4, which has not merged yet. That is fine: this PR does not depend on it landing first. Renovate resolves the preset when it runs, so it will simply pick it up once #4 is in.
How it was verified
What I actually ran:
npx --yes --package renovate@44.46.7 -- renovate-config-validator --strict renovate.json- passes, exit code 0. I sanity-checked the validator by feeding it a config with a bogus option first, and it did report an error, so the pass is meaningful rather than a no-op.npm install --package-lock-onlyand then inspectedgit diff package-lock.json. The diff is exactly 7 deleted lines: thefsentry in the rootdependenciesblock and thenode_modules/fspackage entry. Nothing else in the lockfile moved.grepacross all.ts/.js/.mjsfiles forfsimports. All 21 hits areimport fs from "fs"orimport { readFileSync } from "fs". There are norequire("fs/...")-style or deep-path imports that could have resolved into the placeholder package.Explicitly not verified:
node_modulesis not installed in my working tree (I only ran--package-lock-only, per instructions), and the Playwright suites need self-hosted runners plus Keycloak/Artemis credentials. Thepull_requestruns offunctional-tests.ymlandartemis-integration-tests.ymlon this PR are the real check.renovate-config-validator; it validates schema and syntax only. That the preset path points at a file that exists cannot be confirmed until chore(renovate): add org-wide shared Renovate config .github#4 merges.Deployment impact
Risk and rollback
Low. Nothing here is on an execution path.
The only change with any theoretical bite is dropping
fs, and that is inert: Node's resolver always prefers the builtinfsover a same-named package innode_modules, so no import site changes meaning. If something unexpected does break, revert this commit and runnpm install --package-lock-onlyto restore the entry.renovate.jsonhas no effect at all until Renovate is enabled on the repo. Rollback is deleting the file.Follow-up
A
dependency-reviewcheck will be wired up separately once EduIDE/.github#4 lands. No CI changes in this PR.Summary by CodeRabbit