Skip to content

Add Renovate workflow for Docker base image updates - #86

Merged
ChengYanJin merged 1 commit into
mainfrom
improvement/add-renovate-dockerfile
May 4, 2026
Merged

ChengYanJin merged 1 commit into
mainfrom
improvement/add-renovate-dockerfile

Conversation

@ChengYanJin

Copy link
Copy Markdown
Contributor

Summary

  • Add Renovate configuration to automatically update Docker base images
  • Runs on weekdays at 8am UTC with manual trigger option
  • Auto-approves Renovate PRs via /approve comment
  • Prevents CVE from outdated base layers

Test plan

  • Verify workflow runs successfully on manual trigger
  • Verify Renovate detects Dockerfile base image updates

🤖 Generated with Claude Code

Keep Docker base images up to date automatically to prevent CVE
from outdated base layers. Runs on weekdays at 8am UTC.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings April 30, 2026 16:06

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds Renovate automation to keep Docker base images up to date by introducing a Renovate config and a scheduled GitHub Actions workflow to run Renovate (with an attempted PR auto-approval step).

Changes:

  • Add renovate.json to enable Renovate Dockerfile base image updates and apply labels by update type.
  • Add a scheduled + manually-triggerable GitHub Actions workflow to run Renovate on weekdays at 08:00 UTC.
  • Add a workflow step intended to auto-approve Renovate PRs via a /approve comment.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 4 comments.

File Description
renovate.json Configures Renovate to manage Dockerfile updates and label PRs based on update type.
.github/workflows/renovate.yaml Runs Renovate on a schedule/dispatch and attempts to auto-approve Renovate PRs.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@@ -0,0 +1,44 @@
name: Renovate

Copilot AI Apr 30, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The workflow file is named renovate.yaml, but the existing workflows in this repo use the .yml extension (e.g., docker.yml, release.yml, tests.yml). Consider renaming this to renovate.yml for consistency and easier discovery/grep across workflows.

Copilot uses AI. Check for mistakes.
owner: ${{ github.repository_owner }}

- name: Checkout
uses: actions/checkout@v6

Copilot AI Apr 30, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

actions/checkout@v6 is inconsistent with the rest of the repo’s workflows (which use actions/checkout@v4) and may not be available depending on the Actions release stream. Align this to the same major used elsewhere (or pin to the project’s standard) to avoid workflow failures.

Suggested change
uses: actions/checkout@v6
uses: actions/checkout@v4

Copilot uses AI. Check for mistakes.
Comment on lines +38 to +42
if ! gh pr view "$pr" --repo ${{ github.repository }} --json comments --jq '.comments[].body' | grep -q '^/approve$'; then
gh pr comment "$pr" --repo ${{ github.repository }} --body '/approve'
echo "Approved PR #$pr"
else
echo "PR #$pr already approved, skipping"

Copilot AI Apr 30, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The “Auto-approve Renovate PRs” step doesn’t actually approve PRs in GitHub; it only posts a /approve comment and then logs “Approved PR”. Unless you have an external bot that converts /approve comments into reviews, this won’t satisfy branch protection that requires an approving review. Consider using an actual review approval mechanism (e.g., gh pr review --approve with a token that has pull_requests: write) or rename the step/output to reflect what it really does.

Suggested change
if ! gh pr view "$pr" --repo ${{ github.repository }} --json comments --jq '.comments[].body' | grep -q '^/approve$'; then
gh pr comment "$pr" --repo ${{ github.repository }} --body '/approve'
echo "Approved PR #$pr"
else
echo "PR #$pr already approved, skipping"
if ! gh pr view "$pr" --repo ${{ github.repository }} --json reviews --jq '.reviews[].state' | grep -q '^APPROVED$'; then
gh pr review "$pr" --repo ${{ github.repository }} --approve
echo "Approved PR #$pr"
else
echo "PR #$pr already has an approving review, skipping"

Copilot uses AI. Check for mistakes.
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
run: |
gh pr list --repo ${{ github.repository }} --state open --json number,headRefName --jq '.[] | select(.headRefName | startswith("improvement/renovate-")) | .number' | while read -r pr; do

Copilot AI Apr 30, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This auto-approval logic selects PRs purely by branch prefix, so it will also “approve” Renovate major updates even though the Renovate config distinguishes major updates (adds a major label). If the intent is to only auto-approve safer updates, filter by update type/labels (e.g., only approve when the PR does not have the major label, or only when it has an allowlisted label set).

Suggested change
gh pr list --repo ${{ github.repository }} --state open --json number,headRefName --jq '.[] | select(.headRefName | startswith("improvement/renovate-")) | .number' | while read -r pr; do
gh pr list --repo ${{ github.repository }} --state open --json number,headRefName,labels --jq '.[] | select((.headRefName | startswith("improvement/renovate-")) and ((.labels | map(.name) | index("major")) == null)) | .number' | while read -r pr; do

Copilot uses AI. Check for mistakes.
@ChengYanJin
ChengYanJin merged commit 345ec99 into main May 4, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants