Track Debian apt pins with the Renovate deb datasource - #1133
Conversation
Repology has to be told the source package name, not the binary one,
which is why this repository carried a hand written mapping of
`openssh-client` onto `openssh`. Every future pin whose names differ
would need the same treatment, and getting it wrong fails silently.
The native deb datasource reads the Debian package indices directly and
indexes binary names, so `depNameTemplate` becomes plain `{{{package}}}`
and the mapping goes away. The registry URLs mirror the apt sources in
`ghcr.io/hassio-addons/debian-base:9.4.0` one for one: trixie and
trixie-updates from deb.debian.org/debian, and trixie-security from
deb.debian.org/debian-security, all main, all amd64.
The datasource currently hardcodes `Packages.gz`, which only the trixie
suite serves; trixie-updates and trixie-security serve `Packages.xz` and
return 404 for the gzipped index. Those two suites are therefore inert
until renovatebot/renovate#44330 is resolved. They are kept in the
configuration so it stays a truthful description of what the image
actually pulls from, and lookups that fail are skipped per component, so
trixie keeps working.
All 22 pins exist in trixie main, so nothing stops being tracked. Four of
them, openssl, unzip, uuid-runtime and zip, are currently pinned to
trixie-security versions that are ahead of main, so they stay where they
are until a point release folds them in. Renovate does not roll back by
default, so no downgrade is proposed in the meantime.
Validated with renovate-config-validator from Renovate 44, and the
manager regex checked against the Dockerfile to confirm it still picks up
all 22 pins.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 4 included reviews per hour; 1 remains after this review. WalkthroughRenovate now tracks Debian packages with the ChangesDebian Renovate configuration
Estimated code review effort: 2 (Simple) | ~10 minutes Merge Risk: ⚪ Minimal · up to This localized configuration change switches Debian pin tracking to Renovate’s native Debian datasource without introducing an actionable merge-blocking risk; it is merge-ready after normal checks and review. Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Full details: Docstring CoverageExplanation No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.) ✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Proposed Changes
Ports hassio-addons/app-vaultwarden#447 to this app.
Repology indexes source package names, so it has to be told that
openssh-clientlives in theopensshsource package, which is why this repository carried a hand written mapping indepNameTemplate. Every future pin whose binary and source names differ needs the same treatment, and getting it wrong fails silently: the package simply stops being updated.Renovate's native
debdatasource reads the Debian package indices directly and indexes binary names, sodepNameTemplatebecomes plain{{{package}}}and the mapping disappears.The registry URLs are a one to one mirror of the apt sources in
ghcr.io/hassio-addons/debian-base:9.4.0:deb.debian.org/debiantrixiemaindeb.debian.org/debiantrixie-updatesmaindeb.debian.org/debian-securitytrixie-securitymainThe
debdatasource uses amergeregistry strategy, so releases from all three are aggregated rather than first one wins.Known limitation
Same as in the Vaultwarden PR: the datasource hardcodes
Packages.gz, and onlytrixieserves it. Confirmed against the archive:debian/dists/trixie/main/binary-amd64/Packages.gzdebian/dists/trixie-updates/main/binary-amd64/Packages.gzdebian-security/dists/trixie-security/main/binary-amd64/Packages.gzdebian/dists/trixie-updates/main/binary-amd64/Packages.xzdebian-security/dists/trixie-security/main/binary-amd64/Packages.xzSo
trixie-updatesandtrixie-securityare inert for now. This fails gracefully, lookups are caught and skipped per component, and the two suites start working on their own once renovatebot/renovate#44330 lands. They are kept in the configuration so it stays a truthful description of what the image actually pulls from.Impact on this app
Better than in Vaultwarden, as it happens. All 22 pins in
vscode/Dockerfileare present intrixiemain, so nothing stops being tracked:Four of them are currently pinned to
trixie-securityversions that are ahead ofmain:trixiemainopenssl3.5.7-1~deb13u23.5.6-1~deb13u2unzip6.0-29+deb13u16.0-29uuid-runtime2.41.5-0+deb13u12.41-5zip3.0-15+deb13u13.0-15Those four stay where they are until a Debian point release folds the security update into
main, or until the upstream fix lands and the security suite starts resolving. Renovate does not roll back by default, so no downgrade is proposed in the meantime, and the pins keep building exactly as they do today.Verification
renovate-config-validatorfrom Renovate 44:Config validated successfully.vscode/Dockerfileand still extracts all 22 pins with the correct names and versions.apt-cache policyinsidedebian-base:9.4.0, and thetrixiemainversions above come from the publishedPackages.gz.Related Issues
Ports hassio-addons/app-vaultwarden#447.
Upstream: renovatebot/renovate#44330, with renovatebot/renovate#35865 open against it.
Summary by CodeRabbit