Skip to content

feat(ralphex-fe): let Renovate bump Bun and Hugo; drop the manual push-to-master workflow - #134

Merged
gatezh merged 1 commit into
masterfrom
feat/renovate-ralphex-toolchain
Sep 9, 2026
Merged

gatezh merged 1 commit into
masterfrom
feat/renovate-ralphex-toolchain

Conversation

@gatezh

@gatezh gatezh commented Sep 9, 2026

Copy link
Copy Markdown
Owner

ralphex-fe has no mise — it curls Hugo and Bun directly in its Dockerfile, and its published tag is literally bun<BUN>-hugo<HUGO>. So unlike claude-code, these are image-level versions with no per-project layer to set them from.

They were also the only pinned ARGs in the repo without a # renovate: annotation, and that absence is the sole reason update-and-build-ralphex-fe.yml existed.

What changed

Annotated both ARGs and grouped them as ralphex-fe toolchain — automerge on, with the same 3-day soak the non-claude agent tools get.

Bun uses the npm datasource, not github-releases: oven-sh/bun tags releases as bun-v1.4.2, which the existing extractVersion: '^v?(...)' does not strip. The npm bun package publishes bare semver (1.4.2) matching the ARG format directly. Hugo tags as v0.166.0, which the existing rule handles.

Deleted update-and-build-ralphex-fe.yml rather than repairing it. It took version inputs, rewrote the Dockerfile, and pushed the commit straight to master as github-actions[bot].

That was the repo's only direct-push-to-master path, and the reason the planned branch ruleset needed a bypass actor for GitHub Actions — which GitHub does not offer: the bypass picker lists repo roles and installed GitHub Apps, and Actions is built in rather than installed. Rather than work around that with a PAT or a bot identity, this removes the push.

Nothing is lost: Renovate now covers the version bumps, and build-ralphex-fe.yml already has workflow_dispatch for manual rebuilds.

READMEs updated where they documented driving the deleted workflow — replaced with how to force a rebuild and how to change a pinned version (edit the ARG, open a PR).

Heads-up

The first Renovate PR from this will be a real jump, not a no-op:

Current Latest
Bun 1.3.9 1.4.2
Hugo 0.156.0 0.166.0

It will auto-merge on green and republish the image. Worth watching that one rather than letting it sail through.

Verification

  • actionlint — clean.
  • hadolint on ralphex-fe/Dockerfile with the repo's .hadolint.yaml — clean.
  • renovate-config-validator (official image, validated as repo config) — "Config validated successfully".
  • The customManager matchString exercised against both Dockerfiles, since config validation does not test the regex against real files:
--- ralphex-fe/Dockerfile ---
  bun                        npm              current=1.3.9
  gohugoio/hugo              github-releases  current=0.156.0
  rtk-ai/rtk                 github-releases  current=0.48.0
  umputun/ralphex            github-releases  current=1.7.0
  @anthropic-ai/claude-code  npm              current=2.1.266

Both new entries extract with the right datasource and current value, and the four existing tools still match.

Note

docs/plans/ and docs/superpowers/ still mention the deleted workflow. Those are historical planning artifacts describing what was true when they were written, so they are deliberately left alone.

…h workflow

ralphex-fe has no mise, and its published tag is literally bun<BUN>-hugo<HUGO>,
so Bun and Hugo are image-level versions with nowhere else to be set. They were
the only pinned ARGs in the repo without a `# renovate:` annotation, and that
absence is the sole reason update-and-build-ralphex-fe.yml existed.

Annotated both and grouped them as "ralphex-fe toolchain" with automerge and the
same 3-day soak the non-claude agent tools get. Bun uses the npm datasource
because oven-sh/bun tags releases as "bun-v1.4.2", which the existing
github-releases extractVersion does not strip; the npm package publishes bare
semver that matches the ARG format directly.

update-and-build-ralphex-fe.yml is deleted rather than fixed. It took version
inputs, rewrote the Dockerfile, and pushed the commit straight to master as
github-actions[bot] -- the one direct-push path in the repo, and the reason a
branch ruleset needed a bypass actor that GitHub does not offer for Actions.
Renovate now covers what it did, and build-ralphex-fe.yml already has
workflow_dispatch for manual rebuilds, so nothing is lost except the
push-to-master.

README sections that documented driving that workflow are replaced with how to
force a rebuild and how to change a pinned version (edit the ARG, open a PR).

Note the first Renovate PR will be a real jump: Bun 1.3.9 -> 1.4.2 and Hugo
0.156.0 -> 0.166.0.

Verified: actionlint clean; hadolint clean on ralphex-fe/Dockerfile;
renovate-config-validator "Config validated successfully"; and the
customManager matchString exercised against both Dockerfiles in Python --
it now extracts bun/npm/1.3.9 and gohugoio/hugo/github-releases/0.156.0
alongside the four existing tools.
@gatezh
gatezh merged commit 51de5b9 into master Sep 9, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant