Skip to content

Disallow packages newer than last 7 days#5247

Open
harshil21 wants to merge 2 commits into
masterfrom
renovate/reconfigure
Open

Disallow packages newer than last 7 days#5247
harshil21 wants to merge 2 commits into
masterfrom
renovate/reconfigure

Conversation

@harshil21
Copy link
Copy Markdown
Member

Closes #5195

@harshil21 harshil21 added the ⚙️ security affected functionality: security label May 27, 2026
@renovate
Copy link
Copy Markdown
Contributor

renovate Bot commented May 27, 2026

Reconfigure PR Results

This is a reconfigure PR comment to help you understand and re-configure your renovate bot settings. If this Reconfigure PR were to be merged, we'd expect to see the following outcome:


Detected Package Files

  • .github/workflows/chango.yml (github-actions)
  • .github/workflows/copilot-setup-steps.yml (github-actions)
  • .github/workflows/docs-admonitions.yml (github-actions)
  • .github/workflows/docs-linkcheck.yml (github-actions)
  • .github/workflows/gha_security.yml (github-actions)
  • .github/workflows/lock.yml (github-actions)
  • .github/workflows/prek.yml (github-actions)
  • .github/workflows/release_pypi.yml (github-actions)
  • .github/workflows/release_test_pypi.yml (github-actions)
  • .github/workflows/stale.yml (github-actions)
  • .github/workflows/test_official.yml (github-actions)
  • .github/workflows/type_completeness.yml (github-actions)
  • .github/workflows/type_completeness_monthly.yml (github-actions)
  • .github/workflows/unit_tests.yml (github-actions)
  • pyproject.toml (pep621)
  • .pre-commit-config.yaml (pre-commit)

Configuration Summary

Based on the default config's presets, Renovate will:

  • Hopefully safe environment variables to allow users to configure.
  • Show all Merge Confidence badges for pull requests.
  • Enable Renovate Dependency Dashboard creation.
  • Use semantic commit type fix for dependencies and chore for all others if semantic commits are in use.
  • Ignore node_modules, bower_components, vendor and various test/tests (except for nuget) directories.
  • Group known monorepo packages together.
  • Use curated list of recommended non-monorepo package groupings.
  • Show only the Age and Confidence Merge Confidence badges for pull requests.
  • Apply crowd-sourced package replacement rules.
  • Apply crowd-sourced workarounds for known problems with packages.
  • Ensure that every dependency pinned by digest and sourced from Forgejo contains a link to the commit-to-commit diff
  • Ensure that every dependency pinned by digest and sourced from Gitea contains a link to the commit-to-commit diff
  • Ensure that every dependency pinned by digest and sourced from GitHub.com and Github enterprise contains a link to the commit-to-commit diff
  • Ensure that every dependency pinned by digest and sourced from GitLab.com contains a link to the commit-to-commit diff
  • Correctly link to the source code for golang.org/x packages
  • Link to pkg.go.dev/... for golang.org/x packages' title
  • Pin Docker digests.
  • Pin github-action digests.
  • Enable Renovate configuration migration PRs when needed.
  • Pin dependency versions for development dependencies.
  • Recommended configuration for abandoned packages, treating packages without a release for 1 year as abandoned, while taking into account community-sourced overrides.
  • Wait until the npm package is three days old before raising the update. This a) introduces a short delay to allow for malware researchers and scanners to (possibly) detect any malicious behaviour in packages, and b) prevents the maintainer and/or NPM from unpublishing a package you already upgraded to, breaking builds.
  • Run lock file maintenance (updates) early Monday mornings.
  • Enable the pre-commit manager.
  • Remove limit for open PRs at any time.
  • Run Renovate on following schedule: * * * * 0

What to Expect

With your current configuration, Renovate will create 13 Pull Requests:

Update dependency astral-sh/uv to v0.11.15
  • Schedule: ["* 0-3 1 * *"]
  • Branch name: renovate/astral-sh-uv-0.x
  • Merge into: master
  • Upgrade astral-sh/uv to 0.11.15
Update dependency sphinxcontrib-mermaid to v2.0.2
  • Schedule: ["* 0-3 1 * *"]
  • Branch name: renovate/sphinxcontrib-mermaid-2.x
  • Merge into: master
  • Upgrade sphinxcontrib-mermaid to ==2.0.2
Update github/codeql-action action to v4.35.5
  • Schedule: ["* 0-3 1 * *"]
  • Branch name: renovate/github-codeql-action-4.x
  • Merge into: master
  • Upgrade github/codeql-action to 9e0d7b8d25671d64c341c19c0152d693099fb5ba
Update actions/stale action to v10.3.0
  • Schedule: ["* 0-3 1 * *"]
  • Branch name: renovate/actions-stale-10.x
  • Merge into: master
  • Upgrade actions/stale to eb5cf3af3ac0a1aa4c9c45633dd1ae542a27a899
Update pypa/gh-action-pypi-publish action to v1.14.0
  • Schedule: ["* 0-3 1 * *"]
  • Branch name: renovate/pypa-gh-action-pypi-publish-1.x
  • Merge into: master
  • Upgrade pypa/gh-action-pypi-publish to cef221092ed1bacb1cc03d23a2d87d1d172e277b
Update sigstore/gh-action-sigstore-python action to v3.3.0
  • Schedule: ["* 0-3 1 * *"]
  • Branch name: renovate/sigstore-gh-action-sigstore-python-3.x
  • Merge into: master
  • Upgrade sigstore/gh-action-sigstore-python to 04cffa1d795717b140764e8b640de88853c92acc
Update test-summary/action action to v2.6
  • Schedule: ["* 0-3 1 * *"]
  • Branch name: renovate/test-summary-action-2.x
  • Merge into: master
  • Upgrade test-summary/action to 37b508cfee6d4d080eedd00b5bb240a6a784a6a5
Update astral-sh/setup-uv action to v8
  • Schedule: ["* 0-3 1 * *"]
  • Branch name: renovate/astral-sh-setup-uv-8.x
  • Merge into: master
  • Upgrade astral-sh/setup-uv to 08807647e7069bb48b6ef5acd8ec9567f424441b
Update codecov/codecov-action action to v6
  • Schedule: ["* 0-3 1 * *"]
  • Branch name: renovate/codecov-codecov-action-6.x
  • Merge into: master
  • Upgrade codecov/codecov-action to e79a6962e0d4c0c17b229090214935d2e33f8354
Update dessant/lock-threads action to v6
  • Schedule: ["* 0-3 1 * *"]
  • Branch name: renovate/dessant-lock-threads-6.x
  • Merge into: master
  • Upgrade dessant/lock-threads to 7266a7ce5c1df01b1c6db85bf8cd86c737dadbe7
Update j178/prek-action action to v2
  • Schedule: ["* 0-3 1 * *"]
  • Branch name: renovate/j178-prek-action-2.x
  • Merge into: master
  • Upgrade j178/prek-action to bdca6f102f98e2b4c7029491a53dfd366469e33d
Update Mypy to v2
  • Schedule: ["* 0-3 1 * *"]
  • Branch name: renovate/major-mypy
  • Merge into: master
  • Upgrade mypy to ==2.1.0
  • Upgrade pre-commit/mirrors-mypy to v2.1.0
Lock file maintenance
  • Schedule: ["* 0-3 1 * *"]
  • Branch name: renovate/lock-file-maintenance
  • Merge into: master
  • Regenerate lock files to use latest dependency versions

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

⚙️ security affected functionality: security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Don't upgrade packages less than 7 days old

1 participant