Ajouter un workflow réutilisable qui valide statiquement un renovate.json avec renovate-config-validator (image officielle renovate/renovate:43) sans jamais lancer Renovate — pour attraper ce qui a gelé le dashboard de tf-depl-kubernetes hier (#419, champ registryUrlsTemplate interdit dans un customManagers entry → config-validation exit 5 sur TOUT le repo).
Ce que ça attrape
violations de schéma / champs inconnus
champs interdits dans customManagers[] (registryUrlsTemplate vs registryUrls)
Repo sans renovate.json → job vert, message "skipping validation" (non-bloquant).
Implémentation
Single job, image renovate/renovate:43, 2 steps : checkout du repo appelant + renovate-config-validator <file> (path paramétrable via input config_path, défaut renovate.json).
## But
Ajouter un workflow réutilisable qui **valide statiquement** un `renovate.json` avec `renovate-config-validator` (image officielle `renovate/renovate:43`) **sans jamais lancer Renovate** — pour attraper ce qui a gelé le dashboard de tf-depl-kubernetes hier (#419, champ `registryUrlsTemplate` interdit dans un customManagers entry → config-validation exit 5 sur TOUT le repo).
## Ce que ça attrape
- violations de schéma / champs inconnus
- champs interdits dans `customManagers[]` (`registryUrlsTemplate` vs `registryUrls`)
- packageRules / regex `matchStrings` malformés
- mauvais `extends` / `ignorePresets`
## Usage (dans un repo consommateur)
```yaml
jobs:
validate:
uses: perso/gitea-pipelines/.gitea/workflows/validate.yaml@main
secrets: inherit
```
Repo sans `renovate.json` → job vert, message "skipping validation" (non-bloquant).
## Implémentation
Single job, image `renovate/renovate:43`, 2 steps : checkout du repo appelant + `renovate-config-validator <file>` (path paramétrable via input `config_path`, défaut `renovate.json`).
New workflow_call workflow (.gitea/workflows/validate.yaml) that a consumer
repo can call to statically validate its renovate.json with
renovate-config-validator inside the official renovate/renovate image.
What it catches before Renovate runs (avoiding the dashboard-freeze class of
bug seen when an invalid config makes every extract fail):
- schema violations / unknown fields
- forbidden fields in customManagers (e.g. registryUrlsTemplate -
registryUrls is the only allowed form)
- malformed packageRules / matchStrings regexes
- bad extends / ignorePresets references
It does NOT run Renovate and does NOT touch dependencies - just parses the
config. Non-blocking when the caller has no renovate.json.
Usage in a repo (.gitea/workflows/renovate.yaml or a dedicated workflow):
jobs:
validate:
uses: perso/gitea-pipelines/.gitea/workflows/validate.yaml@main
opencodecabilloteu
requested review from jcabillot 2026-10-08 16:47:21 -04:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
But
Ajouter un workflow réutilisable qui valide statiquement un
renovate.jsonavecrenovate-config-validator(image officiellerenovate/renovate:43) sans jamais lancer Renovate — pour attraper ce qui a gelé le dashboard de tf-depl-kubernetes hier (#419, champregistryUrlsTemplateinterdit dans un customManagers entry → config-validation exit 5 sur TOUT le repo).Ce que ça attrape
customManagers[](registryUrlsTemplatevsregistryUrls)matchStringsmalformésextends/ignorePresetsUsage (dans un repo consommateur)
Repo sans
renovate.json→ job vert, message "skipping validation" (non-bloquant).Implémentation
Single job, image
renovate/renovate:43, 2 steps : checkout du repo appelant +renovate-config-validator <file>(path paramétrable via inputconfig_path, défautrenovate.json).New workflow_call workflow (.gitea/workflows/validate.yaml) that a consumer repo can call to statically validate its renovate.json with renovate-config-validator inside the official renovate/renovate image. What it catches before Renovate runs (avoiding the dashboard-freeze class of bug seen when an invalid config makes every extract fail): - schema violations / unknown fields - forbidden fields in customManagers (e.g. registryUrlsTemplate - registryUrls is the only allowed form) - malformed packageRules / matchStrings regexes - bad extends / ignorePresets references It does NOT run Renovate and does NOT touch dependencies - just parses the config. Non-blocking when the caller has no renovate.json. Usage in a repo (.gitea/workflows/renovate.yaml or a dedicated workflow): jobs: validate: uses: perso/gitea-pipelines/.gitea/workflows/validate.yaml@main