From d9ef7f83607a6274b0e2047a1bddcee278afd2f6 Mon Sep 17 00:00:00 2001 From: openhands Date: Sun, 27 Sep 2026 19:15:31 +0200 Subject: [PATCH] chore(ci): remove Renovate Dependency updates are handled manually, so the scheduled Renovate job only cost a daily privileged Docker run on the deploy host. The empty cache directory it maintained is gone too, and the operations note now records that updates are manual instead of describing bot behaviour. --- .gitea/workflows/renovate.yaml | 30 ----------------------------- docs/operations/cms-error-center.md | 6 +++--- 2 files changed, 3 insertions(+), 33 deletions(-) delete mode 100644 .gitea/workflows/renovate.yaml diff --git a/.gitea/workflows/renovate.yaml b/.gitea/workflows/renovate.yaml deleted file mode 100644 index bda0645d..00000000 --- a/.gitea/workflows/renovate.yaml +++ /dev/null @@ -1,30 +0,0 @@ -name: Renovate -on: - schedule: - - cron: "0 5 * * *" # Every day at 05:00 UTC - workflow_dispatch: # Manual trigger - -jobs: - renovate: - runs-on: self-hosted - steps: - - name: Fix Git safe directory - run: "git config --global --add safe.directory '*' && git remote set-url origin https://epicnabbo.nl || true" - - name: Install Bash in Alpine - run: "if [ -f /etc/alpine-release ]; then apk add --no-cache bash; fi" - - name: Self-hosted Renovate - run: | - set -e - - # Ensure cache dir exists before Docker starts - mkdir -p /var/tmp/renovate-cache - - docker run --rm \ - --user "$(id -u):$(id -g)" \ - -e RENOVATE_TOKEN="${{ secrets.RENOVATE_TOKEN }}" \ - -e RENOVATE_AUTODISCOVER=false \ - -e RENOVATE_REPOSITORIES="${{ gitea.repository }}" \ - -e RENOVATE_ONBOARDING=false \ - -e LOG_LEVEL=info \ - -v /var/tmp/renovate-cache:/tmp/renovate-cache \ - ghcr.io/renovatebot/renovate:latest diff --git a/docs/operations/cms-error-center.md b/docs/operations/cms-error-center.md index 1395457a..870a4a96 100644 --- a/docs/operations/cms-error-center.md +++ b/docs/operations/cms-error-center.md @@ -56,9 +56,9 @@ Lenis has been removed; the public site now uses native scrolling. Other used runtime libraries remain. Vitest and its coverage provider are upgraded together; `clearMocks: false` preserves initialization-time permission contract assertions. -Renovate uses separate development/UI/Vitest groups with manual merge and a -three-day release age. The existing external Gitea bot configuration is retained. -Node/pnpm upgrades remain coordinated with Docker and the runner toolchain. +Dependency updates are manual: Renovate has been removed, so there is no bot +opening upgrade pull requests. Node/pnpm upgrades remain coordinated with +Docker and the runner toolchain. Obsolete global overrides were removed; a scoped esbuild override remains because Drizzle Kit's loader still resolves a vulnerable legacy development-server build. The two deprecated esbuild-kit packages remain upstream dependencies of Drizzle