chore(renovate): surface release age and changelogs, without gating on them

Three gaps in the Renovate setup, all about having enough information in
front of you at review time:

- The PR table had no Age/Adoption/Passing/Confidence columns. Those are
  Mend's Merge Confidence badges, which self-hosted Renovate only emits
  behind the `mergeConfidence:all-badges` preset. No credentials involved
  — Renovate embeds badge URLs and the browser resolves them on view.
- Release notes came back empty. We run against Gitea, but the packages
  are *released* on GitHub, so changelog lookups were going out
  unauthenticated against a 60/h limit. A scopeless read-only PAT
  (GITHUB_COM_TOKEN secret) lifts that.
- Nothing expressed how settled a release is. Cooling-off is now scaled
  by blast radius: 30 days major, 20 minor, 10 patch/digest.

The age tiers are deliberately advisory. Renovate's default
`internalChecksFilter: strict` would suppress the PR outright until the
version aged in; "none" opens it at the highest version immediately and
leaves a pending stability check behind, so merging ahead of the window
stays a decision rather than a wait.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-07-25 21:45:47 +02:00
parent 4c1bfc052e
commit f36a74246b
2 changed files with 36 additions and 0 deletions

View File

@@ -39,4 +39,9 @@ jobs:
RENOVATE_REPOSITORIES: '["makiolaj/calendula"]'
# Commits/PRs authored as the bot, not a real maintainer.
RENOVATE_GIT_AUTHOR: 'Renovate Bot <renovate@jeanlucmakiola.de>'
# Read-only github.com PAT (no scopes needed). We run on Gitea, but
# nearly every dependency is *released* on GitHub — without this,
# changelog/release-note lookups hit the 60/h anonymous rate limit
# and PRs arrive with an empty "Release Notes" section.
RENOVATE_GITHUB_COM_TOKEN: ${{ secrets.GITHUB_COM_TOKEN }}
LOG_LEVEL: info