Repository navigation
Add Renovate workflow for Docker base image updates - #86
Conversation
Keep Docker base images up to date automatically to prevent CVE from outdated base layers. Runs on weekdays at 8am UTC. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Pull request overview
Adds Renovate automation to keep Docker base images up to date by introducing a Renovate config and a scheduled GitHub Actions workflow to run Renovate (with an attempted PR auto-approval step).
Changes:
- Add
renovate.jsonto enable Renovate Dockerfile base image updates and apply labels by update type. - Add a scheduled + manually-triggerable GitHub Actions workflow to run Renovate on weekdays at 08:00 UTC.
- Add a workflow step intended to auto-approve Renovate PRs via a
/approvecomment.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 4 comments.
| File | Description |
|---|---|
| renovate.json | Configures Renovate to manage Dockerfile updates and label PRs based on update type. |
| .github/workflows/renovate.yaml | Runs Renovate on a schedule/dispatch and attempts to auto-approve Renovate PRs. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| @@ -0,0 +1,44 @@ | |||
| name: Renovate | |||
There was a problem hiding this comment.
The workflow file is named renovate.yaml, but the existing workflows in this repo use the .yml extension (e.g., docker.yml, release.yml, tests.yml). Consider renaming this to renovate.yml for consistency and easier discovery/grep across workflows.
| owner: ${{ github.repository_owner }} | ||
|
|
||
| - name: Checkout | ||
| uses: actions/checkout@v6 |
There was a problem hiding this comment.
actions/checkout@v6 is inconsistent with the rest of the repo’s workflows (which use actions/checkout@v4) and may not be available depending on the Actions release stream. Align this to the same major used elsewhere (or pin to the project’s standard) to avoid workflow failures.
| uses: actions/checkout@v6 | |
| uses: actions/checkout@v4 |
| if ! gh pr view "$pr" --repo ${{ github.repository }} --json comments --jq '.comments[].body' | grep -q '^/approve$'; then | ||
| gh pr comment "$pr" --repo ${{ github.repository }} --body '/approve' | ||
| echo "Approved PR #$pr" | ||
| else | ||
| echo "PR #$pr already approved, skipping" |
There was a problem hiding this comment.
The “Auto-approve Renovate PRs” step doesn’t actually approve PRs in GitHub; it only posts a /approve comment and then logs “Approved PR”. Unless you have an external bot that converts /approve comments into reviews, this won’t satisfy branch protection that requires an approving review. Consider using an actual review approval mechanism (e.g., gh pr review --approve with a token that has pull_requests: write) or rename the step/output to reflect what it really does.
| if ! gh pr view "$pr" --repo ${{ github.repository }} --json comments --jq '.comments[].body' | grep -q '^/approve$'; then | |
| gh pr comment "$pr" --repo ${{ github.repository }} --body '/approve' | |
| echo "Approved PR #$pr" | |
| else | |
| echo "PR #$pr already approved, skipping" | |
| if ! gh pr view "$pr" --repo ${{ github.repository }} --json reviews --jq '.reviews[].state' | grep -q '^APPROVED$'; then | |
| gh pr review "$pr" --repo ${{ github.repository }} --approve | |
| echo "Approved PR #$pr" | |
| else | |
| echo "PR #$pr already has an approving review, skipping" |
| env: | ||
| GH_TOKEN: ${{ steps.app-token.outputs.token }} | ||
| run: | | ||
| gh pr list --repo ${{ github.repository }} --state open --json number,headRefName --jq '.[] | select(.headRefName | startswith("improvement/renovate-")) | .number' | while read -r pr; do |
There was a problem hiding this comment.
This auto-approval logic selects PRs purely by branch prefix, so it will also “approve” Renovate major updates even though the Renovate config distinguishes major updates (adds a major label). If the intent is to only auto-approve safer updates, filter by update type/labels (e.g., only approve when the PR does not have the major label, or only when it has an allowlisted label set).
| gh pr list --repo ${{ github.repository }} --state open --json number,headRefName --jq '.[] | select(.headRefName | startswith("improvement/renovate-")) | .number' | while read -r pr; do | |
| gh pr list --repo ${{ github.repository }} --state open --json number,headRefName,labels --jq '.[] | select((.headRefName | startswith("improvement/renovate-")) and ((.labels | map(.name) | index("major")) == null)) | .number' | while read -r pr; do |
Summary
/approvecommentTest plan
🤖 Generated with Claude Code