ci(renovate): drop unreachable automerge, freeze the macOS runner, track the inline zizmor pin - #38
Merged
Merged
Conversation
…ack the inline zizmor pin Three fixes found while auditing why Renovate had gone quiet (root cause is Silent mode on the Mend side, not this file): - The github-actions group asked for automerge, but the "main protect" ruleset requires an approving review with a bypass limited to org admins. The bot cannot merge, so the PRs sat open on a green CI. Granting the app a bypass would hand it a blanket waiver on every dependency PR, digest bumps of third-party actions included — not a trade this repo's supply-chain posture wants. - runs-on is the SDK we compile against, not the deployment target (that lives in Package.swift). Moving to macos-26 would opt the app into the macOS 26 design language and leave no macOS 15 machine in CI, so it is a product decision rather than a weekly PR. - CI pinned zizmor==1.25.2 inline while the pre-commit hook was already on v1.26.1, despite the comment claiming they match. A regex manager now tracks the pin and groups it with the hook so the two move together. Verified with `renovate --platform=local`: the pin extracts as zizmorcore/zizmor 1.25.2, and macos no longer yields any update.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Audit of the Renovate setup. The reason no dependency PR had landed since 6 July is not in this file: the repo is in Silent mode on the Mend portal, so Renovate runs (v44.29.5, jobs daily), detects everything correctly, but writes nothing back — no branch, no PR, and no refresh of the stale Dependency Dashboard issue (#2). That toggle has to be flipped in the portal.
The audit did surface three real problems here.
automergewas unreachableThe
github-actionsgroup asked for automerge, but themain protectruleset requires one approving review with a bypass limited toOrganizationAdmin. Renovate is not an admin, andallow_auto_mergeis off on the repo, so both merge paths were closed: the PRs would have sat open on a green CI, which reads as "waiting on someone" when nothing could ever happen.The alternative is adding the app to the ruleset bypass list. That grants a blanket review waiver on every Renovate PR, digest bumps of third-party actions included — which sits badly next to the pinned digests, zizmor and betterleaks this repo already runs. Dropped the automerge instead; the bypass remains available if the trade is ever wanted.
The macOS runner is now a deliberate bump
runs-on: macos-15is the build machine, not the minimum supported macOS — that one lives inplatforms: [.macOS(.v15)]inPackage.swiftand Renovate never touches it. But the runner does decide the SDK: linking against the macOS 26 SDK opts the app into the new design language, and it would leave no macOS 15 machine in CI. Product decision, not routine maintenance, so the update is disabled with the reasoning recorded indescription. GitHub will retire themacos-15image eventually; this is a "decide later", not a "never".The inline zizmor pin is now tracked
.github/workflows/ci.ymlpinnedzizmor==1.25.2with a comment stating the version matches the pre-commit hook — the hook was onv1.26.1. No manager could see the inline pin, so the pending hook bump to 1.29.0 would have widened the gap silently. A regex custom manager now tracks it, grouped with the hook so both move in one PR.Verification
renovate-config-validatorpasses. A local extraction (renovate --platform=local) confirms the pin resolves aszizmorcore/zizmor1.25.2(replaceString: "zizmor==1.25.2", v1.30.0-rc1 correctly ignored as a prerelease), and thatmacosis still extracted from the three workflows but no longer produces any update.Once Silent mode is off, four updates are waiting: Sparkle
from: "2.9.5", the github-actions group, betterleaks v1.7.4 and zizmor 1.29.0. The Sparkle PR will bump the constraint inPackage.swiftwithout touchingPackage.resolved(still pinned at 2.9.4) — harmless, since CI runs a bareswift buildand re-resolves.