From 6468a6eaff77d457dba5534f228b40e2854b7be4 Mon Sep 17 00:00:00 2001 From: Cody Waits Date: Mon, 7 Sep 2026 09:56:27 -0400 Subject: [PATCH] feat(gomod): run go mod tidy after Go module updates Without postUpdateOptions gomodTidy, Renovate only adds checksums for the new version on each Go module bump and never removes the old ones. In apk-datasource this left ~118 stale go.sum lines across five OpenTelemetry versions before a manual tidy cleaned them up. gomodTidy is scoped to the gomod manager, so repos without a go.mod are unaffected. --- README.md | 1 + default.json | 1 + 2 files changed, 2 insertions(+) diff --git a/README.md b/README.md index 7923bb7..a796f64 100644 --- a/README.md +++ b/README.md @@ -25,3 +25,4 @@ Add this to your repository's `renovate.json`: | Patch automerge | Enabled | Patch updates auto-merge after checks pass | | GitHub Actions automerge | Minor and patch only | Minor and patch Actions updates auto-merge; major requires manual review | | Vulnerability exemption | 0 seconds | Security remediation PRs bypass the 3-day quarantine | +| Go module tidy | `gomodTidy` | Renovate runs `go mod tidy` after Go module updates so stale `go.sum` entries are pruned instead of accumulating | diff --git a/default.json b/default.json index 0474079..33b3185 100644 --- a/default.json +++ b/default.json @@ -19,6 +19,7 @@ "automerge": true, "commitMessageAction": "lock file maintenance" }, + "postUpdateOptions": ["gomodTidy"], "packageRules": [ { "description": "Keep krypsis-io/.github shared workflows on main, never pin",