Skip to content

Track Debian apt pins with the Renovate deb datasource - #1133

Merged
frenck merged 1 commit into
mainfrom
renovate-deb-datasource
Aug 28, 2026
Merged

frenck merged 1 commit into
mainfrom
renovate-deb-datasource

Conversation

@frenck

@frenck frenck commented Aug 28, 2026 •

Copy link
Copy Markdown
Member

Proposed Changes

(Describe the changes and rationale behind them)

Ports hassio-addons/app-vaultwarden#447 to this app.

Repology indexes source package names, so it has to be told that openssh-client lives in the openssh source package, which is why this repository carried a hand written mapping in depNameTemplate. Every future pin whose binary and source names differ needs the same treatment, and getting it wrong fails silently: the package simply stops being updated.

Renovate's native deb datasource reads the Debian package indices directly and indexes binary names, so depNameTemplate becomes plain {{{package}}} and the mapping disappears.

The registry URLs are a one to one mirror of the apt sources in ghcr.io/hassio-addons/debian-base:9.4.0:

Source Suite Component
deb.debian.org/debian trixie main
deb.debian.org/debian trixie-updates main
deb.debian.org/debian-security trixie-security main

The deb datasource uses a merge registry strategy, so releases from all three are aggregated rather than first one wins.

Known limitation

Same as in the Vaultwarden PR: the datasource hardcodes Packages.gz, and only trixie serves it. Confirmed against the archive:

Index Status
debian/dists/trixie/main/binary-amd64/Packages.gz 200
debian/dists/trixie-updates/main/binary-amd64/Packages.gz 404
debian-security/dists/trixie-security/main/binary-amd64/Packages.gz 404
debian/dists/trixie-updates/main/binary-amd64/Packages.xz 200
debian-security/dists/trixie-security/main/binary-amd64/Packages.xz 200

So trixie-updates and trixie-security are inert for now. This fails gracefully, lookups are caught and skipped per component, and the two suites start working on their own once renovatebot/renovate#44330 lands. They are kept in the configuration so it stays a truthful description of what the image actually pulls from.

Impact on this app

Better than in Vaultwarden, as it happens. All 22 pins in vscode/Dockerfile are present in trixie main, so nothing stops being tracked:

tracked by trixie/main: 22/22   not found: 0

Four of them are currently pinned to trixie-security versions that are ahead of main:

Package Pinned In trixie main
openssl 3.5.7-1~deb13u2 3.5.6-1~deb13u2
unzip 6.0-29+deb13u1 6.0-29
uuid-runtime 2.41.5-0+deb13u1 2.41-5
zip 3.0-15+deb13u1 3.0-15

Those four stay where they are until a Debian point release folds the security update into main, or until the upstream fix lands and the security suite starts resolving. Renovate does not roll back by default, so no downgrade is proposed in the meantime, and the pins keep building exactly as they do today.

Verification

  • renovate-config-validator from Renovate 44: Config validated successfully.
  • The manager regex was run against vscode/Dockerfile and still extracts all 22 pins with the correct names and versions.
  • The suite each pin resolves from was read out of apt-cache policy inside debian-base:9.4.0, and the trixie main versions above come from the published Packages.gz.

Related Issues

(Github link to related issues or pull requests)

Ports hassio-addons/app-vaultwarden#447.

Upstream: renovatebot/renovate#44330, with renovatebot/renovate#35865 open against it.

Summary by CodeRabbit

  • Chores
    • Updated Debian package update tracking to use the Debian package source.
    • Limited package lookups to the supported Debian Trixie repositories and amd64 architecture.

Repology has to be told the source package name, not the binary one,
which is why this repository carried a hand written mapping of
`openssh-client` onto `openssh`. Every future pin whose names differ
would need the same treatment, and getting it wrong fails silently.

The native deb datasource reads the Debian package indices directly and
indexes binary names, so `depNameTemplate` becomes plain `{{{package}}}`
and the mapping goes away. The registry URLs mirror the apt sources in
`ghcr.io/hassio-addons/debian-base:9.4.0` one for one: trixie and
trixie-updates from deb.debian.org/debian, and trixie-security from
deb.debian.org/debian-security, all main, all amd64.

The datasource currently hardcodes `Packages.gz`, which only the trixie
suite serves; trixie-updates and trixie-security serve `Packages.xz` and
return 404 for the gzipped index. Those two suites are therefore inert
until renovatebot/renovate#44330 is resolved. They are kept in the
configuration so it stays a truthful description of what the image
actually pulls from, and lookups that fail are skipped per component, so
trixie keeps working.

All 22 pins exist in trixie main, so nothing stops being tracked. Four of
them, openssl, unzip, uuid-runtime and zip, are currently pinned to
trixie-security versions that are ahead of main, so they stay where they
are until a point release folds them in. Renovate does not roll back by
default, so no downgrade is proposed in the meantime.

Validated with renovate-config-validator from Renovate 44, and the
manager regex checked against the Dockerfile to confirm it still picks up
all 22 pins.
@coderabbitai

coderabbitai Bot commented Aug 28, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: b37e4936-d10c-4b89-b905-6b1cb416791f

📥 Commits

Reviewing files that changed from the base of the PR and between ca1049f and e3bb87f.

📒 Files selected for processing (1)
  • .github/renovate.json

Included review availability: Your plan provides up to 4 included reviews per hour; 1 remains after this review.


Walkthrough

Renovate now tracks Debian packages with the deb datasource. The configuration uses extracted package names and limits amd64 lookups to Debian Trixie, Trixie-updates, and Trixie-security repositories.

Changes

Debian Renovate configuration

Layer / File(s) Summary
Debian package resolution
.github/renovate.json
The custom manager uses the deb datasource and extracted package names. The package rule matches deb dependencies and defines Debian Trixie amd64 repositories.

Estimated code review effort: 2 (Simple) | ~10 minutes

Merge Risk: ⚪ Minimal · up to e3bb8

This localized configuration change switches Debian pin tracking to Renovate’s native Debian datasource without introducing an actionable merge-blocking risk; it is merge-ready after normal checks and review.

Poem

A rabbit checks the package trail

Trixie repos guide the rail
The deb source brings versions near
Updates hop from year to year
Renovate keeps the path clear

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: migrating Debian apt pin tracking to Renovate's native deb datasource.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.)

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch renovate-deb-datasource

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@frenck frenck added enhancement Enhancement of the code, not introducing new features. ci Work that improves the continue integration. maintenance Generic maintenance tasks. labels Aug 28, 2026
@frenck
frenck merged commit 8c48e14 into main Aug 28, 2026
14 of 15 checks passed
@frenck
frenck deleted the renovate-deb-datasource branch August 28, 2026 21:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci Work that improves the continue integration. enhancement Enhancement of the code, not introducing new features. maintenance Generic maintenance tasks.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant