From e0c9b172ce1695fb3dfefb86b087990dda2eb153 Mon Sep 17 00:00:00 2001 From: Hermes Agent Date: Thu, 8 Oct 2026 20:47:00 +0000 Subject: [PATCH] feat: add reusable Renovate config validation workflow New workflow_call workflow (.gitea/workflows/validate.yaml) that a consumer repo can call to statically validate its renovate.json with renovate-config-validator inside the official renovate/renovate image. What it catches before Renovate runs (avoiding the dashboard-freeze class of bug seen when an invalid config makes every extract fail): - schema violations / unknown fields - forbidden fields in customManagers (e.g. registryUrlsTemplate - registryUrls is the only allowed form) - malformed packageRules / matchStrings regexes - bad extends / ignorePresets references It does NOT run Renovate and does NOT touch dependencies - just parses the config. Non-blocking when the caller has no renovate.json. Usage in a repo (.gitea/workflows/renovate.yaml or a dedicated workflow): jobs: validate: uses: perso/gitea-pipelines/.gitea/workflows/validate.yaml@main --- .gitea/workflows/validate.yaml | 32 ++++++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+) create mode 100644 .gitea/workflows/validate.yaml diff --git a/.gitea/workflows/validate.yaml b/.gitea/workflows/validate.yaml new file mode 100644 index 0000000..16ef198 --- /dev/null +++ b/.gitea/workflows/validate.yaml @@ -0,0 +1,32 @@ +name: Renovate Config Validation + +on: + workflow_call: + inputs: + config_path: + description: "Path to the Renovate config to validate (a renovate.json in the calling repo). Non-blocking when absent." + required: false + type: string + default: "renovate.json" + +jobs: + validate: + runs-on: ubuntu-latest + container: renovate/renovate:43 + steps: + - name: Checkout caller repo + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + + - name: Validate the repo's Renovate config + run: | + FILE="${{ inputs.config_path }}" + if [ ! -f "$FILE" ]; then + echo "No Renovate config at $FILE — skipping validation (this repo has no renovate.json)." + exit 0 + fi + echo "Validating $FILE" + # renovate-config-validator parses the file against the official + # Renovate schema and catches: invalid fields, bad regexes in + # customManagers, forbidden *Template fields (e.g. registryUrlsTemplate), + # malformed packageRules, etc. It does NOT run Renovate itself. + renovate-config-validator "$FILE"