From e0c9b172ce1695fb3dfefb86b087990dda2eb153 Mon Sep 17 00:00:00 2001 From: Hermes Agent Date: Thu, 8 Oct 2026 20:47:00 +0000 Subject: [PATCH 1/4] feat: add reusable Renovate config validation workflow New workflow_call workflow (.gitea/workflows/validate.yaml) that a consumer repo can call to statically validate its renovate.json with renovate-config-validator inside the official renovate/renovate image. What it catches before Renovate runs (avoiding the dashboard-freeze class of bug seen when an invalid config makes every extract fail): - schema violations / unknown fields - forbidden fields in customManagers (e.g. registryUrlsTemplate - registryUrls is the only allowed form) - malformed packageRules / matchStrings regexes - bad extends / ignorePresets references It does NOT run Renovate and does NOT touch dependencies - just parses the config. Non-blocking when the caller has no renovate.json. Usage in a repo (.gitea/workflows/renovate.yaml or a dedicated workflow): jobs: validate: uses: perso/gitea-pipelines/.gitea/workflows/validate.yaml@main --- .gitea/workflows/validate.yaml | 32 ++++++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+) create mode 100644 .gitea/workflows/validate.yaml diff --git a/.gitea/workflows/validate.yaml b/.gitea/workflows/validate.yaml new file mode 100644 index 0000000..16ef198 --- /dev/null +++ b/.gitea/workflows/validate.yaml @@ -0,0 +1,32 @@ +name: Renovate Config Validation + +on: + workflow_call: + inputs: + config_path: + description: "Path to the Renovate config to validate (a renovate.json in the calling repo). Non-blocking when absent." + required: false + type: string + default: "renovate.json" + +jobs: + validate: + runs-on: ubuntu-latest + container: renovate/renovate:43 + steps: + - name: Checkout caller repo + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + + - name: Validate the repo's Renovate config + run: | + FILE="${{ inputs.config_path }}" + if [ ! -f "$FILE" ]; then + echo "No Renovate config at $FILE — skipping validation (this repo has no renovate.json)." + exit 0 + fi + echo "Validating $FILE" + # renovate-config-validator parses the file against the official + # Renovate schema and catches: invalid fields, bad regexes in + # customManagers, forbidden *Template fields (e.g. registryUrlsTemplate), + # malformed packageRules, etc. It does NOT run Renovate itself. + renovate-config-validator "$FILE" From ad0d2159452e7b3df4e005edf04d0389eb9dcb31 Mon Sep 17 00:00:00 2001 From: Hermes Agent Date: Thu, 8 Oct 2026 21:09:17 +0000 Subject: [PATCH 2/4] ci: PR checks with central-config validation --- .gitea/workflows/pr.yaml | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) create mode 100644 .gitea/workflows/pr.yaml diff --git a/.gitea/workflows/pr.yaml b/.gitea/workflows/pr.yaml new file mode 100644 index 0000000..0d096b9 --- /dev/null +++ b/.gitea/workflows/pr.yaml @@ -0,0 +1,28 @@ +name: PR Checks +on: + workflow_dispatch: + pull_request: + +jobs: + # validate the consumer-facing workflows答复 lint (YAML/structure) + hadolint-shim: + runs-on: ubuntu-latest + steps: + - name: Lint the workflow yaml files + run: | + # Just ensure the yaml files parse and each uses supported fields + python3 - <<'EOF' + import sys, yaml, glob + bad = 0 + for f in glob.glob('.gitea/workflows/*.yaml'): + with open(f) as fh: + yaml.safe_load(fh.read()) + print(f, 'ok') + sys.exit(1 if bad else 0) + EOF + + # Validate the CENTRAL config.json itself with renovate-config-validator + validate-central-config: + uses: ./.gitea/workflows/validate.yaml + with: + config_path: config.json From cb39a2bb3849087d9f3f97d542c3595937bc199c Mon Sep 17 00:00:00 2001 From: Hermes Agent Date: Thu, 8 Oct 2026 21:09:59 +0000 Subject: [PATCH 3/4] ci: fix PR checks (install pyyaml before parsing) --- .gitea/workflows/pr.yaml | 15 +++++++-------- 1 file changed, 7 insertions(+), 8 deletions(-) diff --git a/.gitea/workflows/pr.yaml b/.gitea/workflows/pr.yaml index 0d096b9..c8a3fdd 100644 --- a/.gitea/workflows/pr.yaml +++ b/.gitea/workflows/pr.yaml @@ -4,24 +4,23 @@ on: pull_request: jobs: - # validate the consumer-facing workflows答复 lint (YAML/structure) - hadolint-shim: + # Validate the workflow yaml files parse (PyYAML via pip only when needed) + yaml-parse: runs-on: ubuntu-latest steps: - - name: Lint the workflow yaml files + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + - name: Parse all workflow yaml files run: | - # Just ensure the yaml files parse and each uses supported fields + pip install pyyaml --quiet python3 - <<'EOF' - import sys, yaml, glob - bad = 0 + import glob, yaml for f in glob.glob('.gitea/workflows/*.yaml'): with open(f) as fh: yaml.safe_load(fh.read()) print(f, 'ok') - sys.exit(1 if bad else 0) EOF - # Validate the CENTRAL config.json itself with renovate-config-validator + # Validate the central config.json itself with renovate-config-validator validate-central-config: uses: ./.gitea/workflows/validate.yaml with: From 315ffb0980fa88c9237274d2524de8daf4419737 Mon Sep 17 00:00:00 2001 From: Hermes Agent Date: Thu, 8 Oct 2026 21:11:10 +0000 Subject: [PATCH 4/4] ci: PR checks in the renovate image (pyyaml + config validator) --- .gitea/workflows/pr.yaml | 15 ++++++--------- 1 file changed, 6 insertions(+), 9 deletions(-) diff --git a/.gitea/workflows/pr.yaml b/.gitea/workflows/pr.yaml index c8a3fdd..c31b016 100644 --- a/.gitea/workflows/pr.yaml +++ b/.gitea/workflows/pr.yaml @@ -4,14 +4,15 @@ on: pull_request: jobs: - # Validate the workflow yaml files parse (PyYAML via pip only when needed) - yaml-parse: + # All workflow yaml parse + renovate-config-validator on central config + validate: runs-on: ubuntu-latest + container: renovate/renovate:43 steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - name: Parse all workflow yaml files + # the renovate image ships its own python + pyyaml run: | - pip install pyyaml --quiet python3 - <<'EOF' import glob, yaml for f in glob.glob('.gitea/workflows/*.yaml'): @@ -19,9 +20,5 @@ jobs: yaml.safe_load(fh.read()) print(f, 'ok') EOF - - # Validate the central config.json itself with renovate-config-validator - validate-central-config: - uses: ./.gitea/workflows/validate.yaml - with: - config_path: config.json + - name: Validate central Renovate config + run: renovate-config-validator config.json