feat: reusable Renovate config validation workflow (renovate-config-validator) #3

Merged
jcabillot merged 4 commits from feat/renovate-config-validate-workflow into main 2026-10-08 17:47:12 -04:00
4 Commits
Author SHA1 Message Date
Hermes Agent 315ffb0980 ci: PR checks in the renovate image (pyyaml + config validator)
PR Checks / validate (pull_request) Successful in 22s
2026-10-08 21:11:10 +00:00
Hermes Agent cb39a2bb38 ci: fix PR checks (install pyyaml before parsing)
Renovate Config Validation / validate (pull_request) Successful in 13s
PR Checks / yaml-parse (pull_request) Failing after 14s
PR Checks / validate-central-config (pull_request) Successful in 13s
2026-10-08 21:09:59 +00:00
Hermes Agent ad0d215945 ci: PR checks with central-config validation
PR Checks / hadolint-shim (pull_request) Failing after 4s
Renovate Config Validation / validate (pull_request) Successful in 1m44s
PR Checks / validate-central-config (pull_request) Successful in 1m44s
2026-10-08 21:09:17 +00:00
Hermes Agent e0c9b172ce feat: add reusable Renovate config validation workflow
New workflow_call workflow (.gitea/workflows/validate.yaml) that a consumer
repo can call to statically validate its renovate.json with
renovate-config-validator inside the official renovate/renovate image.

What it catches before Renovate runs (avoiding the dashboard-freeze class of
bug seen when an invalid config makes every extract fail):
- schema violations / unknown fields
- forbidden fields in customManagers (e.g. registryUrlsTemplate -
  registryUrls is the only allowed form)
- malformed packageRules / matchStrings regexes
- bad extends / ignorePresets references

It does NOT run Renovate and does NOT touch dependencies - just parses the
config. Non-blocking when the caller has no renovate.json.

Usage in a repo (.gitea/workflows/renovate.yaml or a dedicated workflow):

    jobs:
      validate:
        uses: perso/gitea-pipelines/.gitea/workflows/validate.yaml@main
2026-10-08 20:47:00 +00:00