Dependency Automation
BoardReadyOps uses Renovate as the single source of truth for routine version-update pull requests.
Execution
.github/workflows/renovate.ymlvalidatesrenovate.jsonon pull requests and changes tomain. Validation runs the official Renovate image by immutable tagged digest, with the repository mounted read-only and container networking disabled, so validation cannot drift through dynamically resolvedpnpm dlxtransitives.- The workflow
renovate-versioninput is the self-hosted runtime version source of truth. Acustom.regexmanager tracks the validator image tag and digest, and both self-hosted Renovate dependencies are grouped into amanual-reviewexception PR instead of entering the automatic path. - The pinned Renovate runner executes at 06:17 Europe/Istanbul on weekdays and can also be started manually.
- The runner is explicitly scoped to
oaslananka/boardreadyops; repository autodiscovery and onboarding are disabled. - The workflow uses the
GH_AUTH_TOKENrepository secret. That credential must belong to a dedicated automation identity with the minimum repository permissions required to create branches, pull requests, labels, and issues. - Post-upgrade command execution is restricted through
RENOVATE_ALLOWED_COMMANDSto the exactcorepack pnpm run renovate:post-upgradeentry point. That repository-controlled script creates an isolated temporary pnpm store for the dependency install, native rebuild,NOTICErefresh, and committeddist/rebuild, then removes the store. This prevents shared-runner pnpm store metadata from breakingpnpm licenses listwhile keeping Renovate unable to execute arbitrary post-upgrade commands. - Renovate itself never runs on a pull-request event, so untrusted pull-request code cannot obtain the automation token.
Policy layers
renovate.json is self-contained. It directly carries the conservative baseline that BoardReadyOps previously inherited from github>oaslananka/.github:renovate-config: the Europe/Istanbul timezone, seven-day routine release quarantine, strict internal age filtering, two new PRs per hour, five concurrent PRs, digest pinning, weekly lockfile maintenance, semantic commits, Dependency Dashboard, and explicit approval for major upgrades.
This local fallback became authoritative after the scheduled run on October 2, 2026 failed to resolve the shared preset. Keeping the baseline in the repository prevents dependency maintenance from depending on a second repository or on broader token scope. BoardReadyOps-specific schedule, managed package managers, generated NOTICE/dist/ refresh, protected package groups, vulnerability-PR policy, and merge routing remain local as before. Generated output, dependency trees, and test fixtures remain excluded from discovery.
Automatic path
Low-risk development dependency and @types/* non-major updates remain the routine path. Same-version GitHub Action digest refreshes are also routine when they do not touch security, release, provenance, publication, container-release, or binary-release workflows.
Routine classification never bypasses GitHub Rulesets. Required checks must pass and review conversations must be resolved before an explicit maintainer squash merge. The automerge label on low-risk dependency groups is classification metadata only; BoardReadyOps does not enable Renovate's own automerge: true path and Mergify does not queue or merge these pull requests.
Exception path
Major updates, TypeScript, core runtime/GitHub integration dependencies, self-hosted Renovate runtime/validator upgrades, vulnerability-remediation PRs, non-digest GitHub Action updates, Actions changes in protected workflows, and Dockerfile/Docker Compose updates carry manual-review and remain on hold until a maintainer clears the exception.
GitHub Actions and container references remain digest-pinned. Security vulnerability remediation bypasses the routine schedule and release-age wait, requests the lowest known-safe version, and remains manual-review only.
Pull-request creation
Routine minimum-age waiting is enforced by Renovate's strict internal checks before branch creation. BoardReadyOps CI begins on pull_request, not on bare Renovate branches, so the repository does not use prCreation: not-pending; otherwise a dependency branch can wait for checks that cannot start until the pull request exists.
Files
renovate.jsoncontrols project-specific Renovate behavior..github/workflows/renovate.ymlvalidates and runs the pinned self-hosted Renovate release..mergify.ymlprovides pull-request classification plus a manual-onlymainmerge queue; the GitHubmainruleset remains the merge authority.tests/unit/scripts/security-automation-config.test.tsprevents accidental weakening of the automation contract.- Version-update PR configuration must not be duplicated in another dependency updater.
Last verification
- On October 4, 2026, Mergify was configured as a manual-only queue: there is no auto-merge/auto-queue condition, and a maintainer must explicitly enqueue a PR with
@mergifyio queue main. GitHub Rulesets remain authoritative for merge eligibility and required checks. - On July 20, 2026, Renovate
43.272.4completed a full dry-run under Node.js24.18.0. - The repository reported
activated,enabled, andonboarded, and Renovate discovered 269 dependencies across npm, GitHub Actions, Dockerfiles, and Docker Compose. - After the workflow reached
main, manual workflow run29767533207completed bothrenovate / validateandrenovate / runsuccessfully. - The authenticated run created Dependency Dashboard issue
#196and populated pending-approval, awaiting-schedule, status-check, abandoned-dependency, and detected-dependency sections. - No update branches or pull requests were created outside the configured schedule or approval policy.
- On September 17, 2026, the shared
oaslananka/.githubpreset was verified at commitc44946c82eeb6c5041dbc94f371c55015679cbe0(renovate-config.jsonblob6ad5d7c7232908a686a4b9e0404fb30f4d30c2da). - On October 2, 2026, scheduled run
36992286708failed before repository processing because that shared preset could no longer be resolved. BoardReadyOps therefore activated the documented repository-local recovery path instead of wideningGH_AUTH_TOKENaccess to another repository. - BoardReadyOps implementation PR
#819merged through Mergify'sdefaultqueue after themainRuleset conditions, includingci / risk-profileandsecurity / gate, were satisfied. - Post-merge manual Renovate workflow run
35251461740ran against merge commit6e5a7b020a335a19b57ec251969d4dd8f84efa20; bothrenovate / validateandrenovate / runcompleted successfully. - Dependency Dashboard
#196updated at2026-09-17T17:16:35Z. No Renovate or Dependabot PR remained open after the run; routine developer-tooling, type-definition, and lockfile updates were awaiting their schedule while major updates remained pending approval. - No representative low-risk dependency PR auto-entered Mergify during this verification because the run created no PR outside the configured schedule. The next naturally eligible low-risk Renovate PR remains the live queue/merge acceptance sample.
Operations
- Confirm the repository-local conservative baseline remains present in
renovate.json; do not reintroduce an external preset dependency without a separately verified availability and credential contract. - Run
corepack pnpm run renovate:validateafter policy changes. - Confirm
security-automation-config.test.tsandmergify-integration.test.tspass. - Confirm
manual-reviewis present on protected updates and absent from an eligible low-risk update. - Confirm the PR receives the repository's required Ruleset checks and that review conversations are resolved.
- After the PR is intentionally approved for merge, enqueue it with
@mergifyio queue main(or the Mergify queue control). Do not enable Mergify auto-merge/auto-queue; an open green PR should remain open until a maintainer explicitly queues it. - Run the Renovate workflow manually after first installation or credential rotation and confirm the Dependency Dashboard can be updated.
- Rotate
GH_AUTH_TOKENimmediately if its owner or permissions change unexpectedly.