Files
calendula/renovate.json5
Jean-Luc Makiola 98a3335975
All checks were successful
Translations / check (pull_request) Successful in 5s
CI / ci (pull_request) Successful in 5m33s
chore(renovate): compute the PR Age column ourselves
The Age badge was already there — config:recommended pulls in
mergeConfidence:age-confidence-badges — it just rendered as a grey
UNKNOWN. Fetching the badge SVGs from developer.mend.io directly shows
why: Mend's Merge Confidence index covers Maven Central (truth 2y,
junit-jupiter 1y, kotlin-stdlib 1y / confidence high / passing 99%) but
has nothing for anything served off Google's Maven repo, so every
androidx and compose coordinate comes back UNKNOWN. That's the bulk of
this project, and no token changes it — the JSON API behind the badges
answers 401 for everyone, npm included.

So take the age from the one place that does know. Renovate derives
release timestamps itself to evaluate minimumReleaseAge, and Google
Maven serves last-modified on its POMs, so newVersionAgeInDays is
populated where Mend is blank. Redefining the column costs one template
and makes the number agree with the cooling-off tiers it's read against.

Mend keeps the Confidence column, which still resolves for the Maven
Central half — Kotlin, Gradle, AGP, the test stack — and those are the
bumps where a compatibility signal is worth having. Dropped the
all-badges preset added in the previous commit: Adoption and Passing
have the same Google Maven gap, so they'd have been two more empty
columns. A trailing packageRule pins the same column set for every PR,
including the Gradle wrapper and Actions bumps that Mend's preset never
touched and which showed no age at all.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-25 22:00:56 +02:00

109 lines
4.3 KiB
Plaintext

{
$schema: "https://docs.renovatebot.com/renovate-schema.json",
extends: [
"config:recommended",
// chore(deps): … — match the repo's conventional-commit style.
":semanticCommits",
],
// `config:recommended` brings in mergeConfidence:age-confidence-badges, whose
// Age column is a Mend badge. Mend's Merge Confidence index only covers Maven
// Central: org.jetbrains.kotlin, junit, truth, turbine et al resolve, but
// every androidx/compose artifact lives on Google's Maven repo and comes back
// as a grey UNKNOWN — i.e. most of this project. Renovate already knows the
// real answer, since it derives release timestamps itself for the
// minimumReleaseAge rules below (Google Maven serves `last-modified` on its
// POMs), so take the age from there and leave Mend to the Confidence column,
// which still carries signal for the Maven Central half.
prBodyDefinitions: {
Age: "{{#if releaseTimestamp}}{{{newVersionAgeInDays}}} d{{else}}unknown{{/if}}",
},
// Default heading links to the Merge Confidence docs; this column is ours now.
prBodyHeadingDefinitions: {
Age: "Age",
},
// No automerge: a dependency bump goes through the same review (and, for
// anything touching the build, the same on-device check) as a feature
// before it can ride a release — see docs/RELEASING.md and the
// "hold release for approval" rule.
automerge: false,
// One reviewable surface; the dashboard issue lists everything pending.
dependencyDashboard: true,
// The cooling-off periods below are advisory, not a gate: "none" turns off
// filtering on the minimumReleaseAge check, so the PR is opened at the
// highest version straight away and merging early stays a judgement call.
// (Renovate's default here is "strict", which suppresses the PR entirely
// until the release has aged in.) A still-young release carries a pending
// `renovate/stability-days` check so it's visible which side of the line
// it's on; with automerge off, nothing acts on that check by itself.
internalChecksFilter: "none",
labels: ["dependencies"],
prConcurrentLimit: 5,
prHourlyLimit: 0,
// Cadence is owned by the Gitea Actions cron (.gitea/workflows/renovate.yml,
// Mondays) — no internal `schedule` here, so the two don't double-gate and
// silently skip a run.
// Gitea Actions workflows live under .gitea/workflows, not .github — extend
// the github-actions manager (same syntax) to watch them too.
"github-actions": {
fileMatch: ["^\\.gitea/workflows/[^/]+\\.ya?ml$"],
},
packageRules: [
// Cooling-off period, scaled by blast radius: how long a release should
// have been out (and un-yanked, un-hotfixed) before it's considered
// settled. Advisory only — see `internalChecksFilter` above.
{
matchUpdateTypes: ["major"],
minimumReleaseAge: "30 days",
},
{
matchUpdateTypes: ["minor"],
minimumReleaseAge: "20 days",
},
{
matchUpdateTypes: ["patch", "digest", "pin", "rollback"],
minimumReleaseAge: "10 days",
},
// material3 is deliberately pinned to the 1.5 *alpha* line for the
// Expressive APIs (see gradle/libs.versions.toml). Follow the alpha train
// but keep it in its own PR, reviewed in isolation; revisit the pin when
// 1.5.0 stable lands.
{
matchPackageNames: ["androidx.compose.material3:material3"],
ignoreUnstable: false,
groupName: "material3 (alpha)",
},
// Test-only deps: group into one low-noise PR.
{
matchPackageNames: [
"org.junit.jupiter:**",
"org.junit.platform:**",
"com.google.truth:**",
"app.cash.turbine:**",
"androidx.test:**",
"androidx.test.espresso:**",
"androidx.test.ext:**",
],
groupName: "test dependencies",
},
// Last word on the PR table. The merge-confidence preset sets prBodyColumns
// from inside a packageRule of its own, and only for the datasources Mend
// supports — so a plain top-level prBodyColumns would lose to it for maven
// deps, and the Gradle wrapper / Actions / container bumps would keep the
// default columns and show no age at all. A rule declared after it wins,
// and gives every PR the same table.
{
matchPackageNames: ["*"],
prBodyColumns: ["Package", "Type", "Change", "Age", "Confidence"],
},
],
}