diff --git a/.gitea/workflows/pr.yaml b/.gitea/workflows/pr.yaml new file mode 100644 index 0000000..c31b016 --- /dev/null +++ b/.gitea/workflows/pr.yaml @@ -0,0 +1,24 @@ +name: PR Checks +on: + workflow_dispatch: + pull_request: + +jobs: + # All workflow yaml parse + renovate-config-validator on central config + validate: + runs-on: ubuntu-latest + container: renovate/renovate:43 + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + - name: Parse all workflow yaml files + # the renovate image ships its own python + pyyaml + run: | + python3 - <<'EOF' + import glob, yaml + for f in glob.glob('.gitea/workflows/*.yaml'): + with open(f) as fh: + yaml.safe_load(fh.read()) + print(f, 'ok') + EOF + - name: Validate central Renovate config + run: renovate-config-validator config.json diff --git a/.gitea/workflows/validate.yaml b/.gitea/workflows/validate.yaml new file mode 100644 index 0000000..16ef198 --- /dev/null +++ b/.gitea/workflows/validate.yaml @@ -0,0 +1,32 @@ +name: Renovate Config Validation + +on: + workflow_call: + inputs: + config_path: + description: "Path to the Renovate config to validate (a renovate.json in the calling repo). Non-blocking when absent." + required: false + type: string + default: "renovate.json" + +jobs: + validate: + runs-on: ubuntu-latest + container: renovate/renovate:43 + steps: + - name: Checkout caller repo + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + + - name: Validate the repo's Renovate config + run: | + FILE="${{ inputs.config_path }}" + if [ ! -f "$FILE" ]; then + echo "No Renovate config at $FILE — skipping validation (this repo has no renovate.json)." + exit 0 + fi + echo "Validating $FILE" + # renovate-config-validator parses the file against the official + # Renovate schema and catches: invalid fields, bad regexes in + # customManagers, forbidden *Template fields (e.g. registryUrlsTemplate), + # malformed packageRules, etc. It does NOT run Renovate itself. + renovate-config-validator "$FILE"