Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Feature: Renovate for Dependency Management

オープン
#750 コメント 2 件 リアクション 3 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
35/100
issue の種類
機能追加
明瞭さ
おおむね明確
活発さ
停滞
技術スタック
github-actions, helm
領域
ci-cd, devops

調査の方向性

提案されている Renovate 設定と Renovate の GitHub Marketplace 統合から始め、その後、リポジトリで Helm チャート、ワークフロー、lockfile がどのように扱われているかを確認します。合意された Renovate セットアップが統合され、依存関係の更新が意図したとおりに生成され、automerge の動作がリポジトリの CI チェックでカバーされていれば完了です。

索引モデルが issue の本文から書いたものです。

説明

enhancement

Description of the change

Similar to what I have seen, and done in other repositories, I believe it would be beneficial to get renovate on this repository.

It will generate PRs like this one for example: https://gitlab.com/GeorgeRaven/raven-helm-charts/-/merge_requests/201, so that we can automate a significant portion of the maintenance work related to updating patches etc.

I extend renovate with custom managers so we can manage the version of anything in any file using regex.

This is my generic configuration that handles 90% of my use cases in my repositories:

{
    "$schema": "https://docs.renovatebot.com/renovate-schema.json",
    "extends": [
        "config:recommended"
    ],
    "packageRules": [
        {
            "description": "Automerge patches",
            "excludePackageNames": [],
            "matchUpdateTypes": [
                "patch"
            ],
            "matchCurrentVersion": "!/^0/",
            "automerge": true
        }
    ],
    "customManagers": [
        {
            "customType": "regex",
            "managerFilePatterns": [
                "/^.*$/"
            ],
            "matchStrings": [
                "\"?v?(?<currentValue>(?<major>0|[1-9]\\d*)\\.(?<minor>0|[1-9]\\d*)\\.(?<patch>0|[1-9]\\d*)(?:-(?<prerelease>(?:0|[1-9]\\d*|\\d*[a-zA-Z-][0-9a-zA-Z-]*)(?:\\.(?:0|[1-9]\\d*|\\d*[a-zA-Z-][0-9a-zA-Z-]*))*))?(?:\\+(?<buildmetadata>[0-9a-zA-Z-]+(?:\\.[0-9a-zA-Z-]+)*))?)\"?\\s+# renovate: datasource=(?<datasource>.*) depName=(?<depName>.*)"
            ],
            "extractVersionTemplate": "^v?(?<version>.*)$"
        }
    ]
}

The only thing to note is the addition of an automerge rule, this will create and automate merging of semver patches. Thus eliminating the maintenance of and keeping on top of them.

Benefits

  • higher automation, reducing maintenance work
  • ensures all dependencies can be managed even those in non-standard locations that might be forgotten about
  • works with just about everything, helm, github workflows, lockfiles, etc
  • highly configurable depending on what everyone would like to see, including automated bumping of helm package versions, when a sub-dependency is updated.

Possible drawbacks

  • higher automation in particular patch automerging requires good Ci setup to ensure a high-bar of trust in merges. (This will be a seperate issue I will likely open shortly to do with kubeconform etc)
  • while I can self-host it, I would probably recommend that it is added to the github repo directly via the marketplace: https://github.com/marketplace/renovate/ for long-term support.
  • some level of trust is required in renovate to give it access to create branches, from which it creates PRs to the default branch (unless otherwise specified)

Additional information

There are many ways to skin the proverbial renovate cat. Please let me know what you think.

主要言語
Go Template
スター
536
フォーク
316
平均マージ
4日 16時間
マージ済み PR(30日)
2

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

nextcloud/helm のほかの issue

nextcloud/helm の issue をすべて見る

似ている issue

DevOps の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。