Hermes Agent e0c9b172ce feat: add reusable Renovate config validation workflow
New workflow_call workflow (.gitea/workflows/validate.yaml) that a consumer
repo can call to statically validate its renovate.json with
renovate-config-validator inside the official renovate/renovate image.

What it catches before Renovate runs (avoiding the dashboard-freeze class of
bug seen when an invalid config makes every extract fail):
- schema violations / unknown fields
- forbidden fields in customManagers (e.g. registryUrlsTemplate -
  registryUrls is the only allowed form)
- malformed packageRules / matchStrings regexes
- bad extends / ignorePresets references

It does NOT run Renovate and does NOT touch dependencies - just parses the
config. Non-blocking when the caller has no renovate.json.

Usage in a repo (.gitea/workflows/renovate.yaml or a dedicated workflow):

    jobs:
      validate:
        uses: perso/gitea-pipelines/.gitea/workflows/validate.yaml@main
2026-10-08 20:47:00 +00:00
2026-08-02 18:56:25 -04:00

renovate-bot

Central Renovate configuration for all repos on scm.cabillot.eu.

How it works

This repo (public) contains:

  • config.json — global Renovate config (no secrets, only placeholders resolved at runtime)
  • .gitea/workflows/renovate.yaml — reusable Gitea Actions workflow (workflow_call)

Being public allows the Gitea Actions runner to clone this repo for reusable workflow calls. No secrets are stored here — they come from org-level secrets on the calling repo's org.

Adopting Renovate in a repo

Add this workflow file to your repo at .gitea/workflows/renovate.yaml:

name: Renovate

on:
  schedule:
    - cron: '0 0 */2 * *'
  push:
    branches:
      - main
  workflow_dispatch:

jobs:
  renovate:
    uses: perso/renovate-bot/.gitea/workflows/renovate.yaml@main
    secrets: inherit

That's it. Renovate will:

  • Scan every 2 days for dependency updates
  • Re-run on every push to main (after merges) to rebase stale PRs
  • Be triggerable manually via workflow_dispatch (UI or API)

Per-repo overrides

Add a renovate.json at the root of your repo. It will be merged with the global config.

Required secrets

These must be set as org-level secrets in the Gitea org of the consumer repo:

Secret Purpose
RENOVATE_TOKEN Gitea API token for the renovate bot
RENOVATE_GITHUB_TOKEN GitHub token for GitHub-hosted dependencies
RENOVATE_SSH_KEY SSH private key for git operations (optional)
S
Description
Central Pipeline configuration
Readme
35 KiB
0 Stars 5 Watchers 0 Forks