Repository navigation
feat(ralphex-fe): let Renovate bump Bun and Hugo; drop the manual push-to-master workflow - #134
Merged
Merged
Conversation
…h workflow ralphex-fe has no mise, and its published tag is literally bun<BUN>-hugo<HUGO>, so Bun and Hugo are image-level versions with nowhere else to be set. They were the only pinned ARGs in the repo without a `# renovate:` annotation, and that absence is the sole reason update-and-build-ralphex-fe.yml existed. Annotated both and grouped them as "ralphex-fe toolchain" with automerge and the same 3-day soak the non-claude agent tools get. Bun uses the npm datasource because oven-sh/bun tags releases as "bun-v1.4.2", which the existing github-releases extractVersion does not strip; the npm package publishes bare semver that matches the ARG format directly. update-and-build-ralphex-fe.yml is deleted rather than fixed. It took version inputs, rewrote the Dockerfile, and pushed the commit straight to master as github-actions[bot] -- the one direct-push path in the repo, and the reason a branch ruleset needed a bypass actor that GitHub does not offer for Actions. Renovate now covers what it did, and build-ralphex-fe.yml already has workflow_dispatch for manual rebuilds, so nothing is lost except the push-to-master. README sections that documented driving that workflow are replaced with how to force a rebuild and how to change a pinned version (edit the ARG, open a PR). Note the first Renovate PR will be a real jump: Bun 1.3.9 -> 1.4.2 and Hugo 0.156.0 -> 0.166.0. Verified: actionlint clean; hadolint clean on ralphex-fe/Dockerfile; renovate-config-validator "Config validated successfully"; and the customManager matchString exercised against both Dockerfiles in Python -- it now extracts bun/npm/1.3.9 and gohugoio/hugo/github-releases/0.156.0 alongside the four existing tools.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
ralphex-fehas nomise— itcurls Hugo and Bun directly in its Dockerfile, and its published tag is literallybun<BUN>-hugo<HUGO>. So unlikeclaude-code, these are image-level versions with no per-project layer to set them from.They were also the only pinned
ARGs in the repo without a# renovate:annotation, and that absence is the sole reasonupdate-and-build-ralphex-fe.ymlexisted.What changed
Annotated both ARGs and grouped them as
ralphex-fe toolchain— automerge on, with the same 3-day soak the non-claude agent tools get.Bun uses the npm datasource, not
github-releases:oven-sh/buntags releases asbun-v1.4.2, which the existingextractVersion: '^v?(...)'does not strip. The npmbunpackage publishes bare semver (1.4.2) matching the ARG format directly. Hugo tags asv0.166.0, which the existing rule handles.Deleted
update-and-build-ralphex-fe.ymlrather than repairing it. It took version inputs, rewrote the Dockerfile, and pushed the commit straight tomasterasgithub-actions[bot].That was the repo's only direct-push-to-master path, and the reason the planned branch ruleset needed a bypass actor for GitHub Actions — which GitHub does not offer: the bypass picker lists repo roles and installed GitHub Apps, and Actions is built in rather than installed. Rather than work around that with a PAT or a bot identity, this removes the push.
Nothing is lost: Renovate now covers the version bumps, and
build-ralphex-fe.ymlalready hasworkflow_dispatchfor manual rebuilds.READMEs updated where they documented driving the deleted workflow — replaced with how to force a rebuild and how to change a pinned version (edit the ARG, open a PR).
Heads-up
The first Renovate PR from this will be a real jump, not a no-op:
It will auto-merge on green and republish the image. Worth watching that one rather than letting it sail through.
Verification
actionlint— clean.hadolintonralphex-fe/Dockerfilewith the repo's.hadolint.yaml— clean.renovate-config-validator(official image, validated as repo config) — "Config validated successfully".matchStringexercised against both Dockerfiles, since config validation does not test the regex against real files:Both new entries extract with the right datasource and current value, and the four existing tools still match.
Note
docs/plans/anddocs/superpowers/still mention the deleted workflow. Those are historical planning artifacts describing what was true when they were written, so they are deliberately left alone.