Org-wide Renovate shared presets for FlowMatrix-AI.
Safe for any repo type (Node, Python, Terraform, etc.). Provides:
- Weekly schedule (before 7am Monday, Eastern)
dependencieslabel on PRs- Max 5 concurrent PRs
- Renovate's
config:recommendedbase - Supply-chain cooldown:
minimumReleaseAge: "3 days"— a freshly published version is not eligible until it has been public for 3 days, reducing exposure to compromised/yanked releases. Applies to all managers (npm, GitHub Actions, etc.). internalChecksFilter: "strict"— holds branches/PRs until internal checks (including the release-age cooldown) pass, so automerge can never fire before the cooldown elapses.osvVulnerabilityAlerts: true— vulnerability alerts from the OSV database in addition to GitHub advisories.constraints.npm: "^12"— the npm Renovate runs when it regenerates a lockfile. It must satisfy everyengines.npmfloor in the fleet (several sites declare>=12.0.2), or Renovate writes lockfiles with an npm the repo says it does not support.engines.npmitself is not managed by Renovate (see the rule indefault.json), so move this constraint by hand when the fleet's floor moves. npm 12 changed theallow-remotedefault fromalltonone, and then refuses to fetch a lockfile entry with a tarball URL (tailwind 4's@tailwindcss/oxide-wasm32-wasiis one, in every site). Thenpmrcindefault.jsonandnpmjs-scope.jsontherefore carriesallow-remote=all, npm 11's default. That reaches every consumer: withnpmrcMergeoff (the default), Renovate uses the presetnpmrcin place of a repo's own.npmrc.- TypeScript majors held behind Dependency-Dashboard approval. TS 7 is a
native compiler that does not yet ship the programmatic API
astro checkloads, and it also breaks plain workspace typechecks and at least one app build. The hold keeps the major visible and one-click on the dashboard rather than silently dropping it. Minor and patch still flow normally.
Usage:
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": ["local>FlowMatrix-AI/renovate-config"]
}Extends default. For repos consuming @flowmatrix-ai/site-components. Adds:
- GitHub Packages registry auth (
npm.pkg.github.comvia Renovate App token) - Non-major npm updates: grouped, automerged
- Non-major GitHub Actions: grouped, automerged
- Tailwind packages: grouped, automerged (non-major only — see guard below)
@flowmatrix-ai/*internal packages: grouped, not automerged (manual review)- Lock file maintenance: automerged
- Major-update safety guard: a final
packageRuleforcesautomerge: falsefor everymajorupdate, so no group rule can ever automerge a breaking version. Combined with the baseline cooldown, automerges are both delayed and non-major-only.
Usage:
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": ["local>FlowMatrix-AI/renovate-config:marketing-site"]
}A single-purpose fragment, meant to be extended alongside another preset:
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": [
"local>FlowMatrix-AI/renovate-config",
"local>FlowMatrix-AI/renovate-config:npmjs-scope"
]
}Use it in any repo whose @flowmatrix-ai dependencies are all on npmjs — since
2026-08-31 that is everything except site-generator and the eight
checkout-* packages.
Why it is load-bearing. default.json sets npmrc for the whole scope, and
that is not merely a lookup setting: it is what Renovate hands to npm/pnpm
when it regenerates a lockfile, so it decides the resolved URLs that get
committed. A repo that has dropped its .npmrc but still inherits that npmrc
gets its lockfile quietly rewritten back to GitHub Packages on the next lock
refresh, and the next install fails with 401 Unauthorized. The registryUrls
packageRule does not prevent this — it governs version lookup only.
Observed twice on 2026-08-31: site-marketfourseasons-main#66 and, after the
brand migration, flowmatrixai-org#21.
A repo consuming any GitHub-Packages-only package must not extend this: npm maps a registry per scope, not per package.
marketing-site plus npmjs-scope — identical to marketing-site except that
the @flowmatrix-ai scope points at registry.npmjs.org.
Use this preset once a site's package-lock.json no longer contains any
npm.pkg.github.com URL. On marketing-site, lock file maintenance rewrites
those entries back to GitHub Packages — see Auth for private
packages — and the next npm ci fails with
401 Unauthorized.
A site that still consumes a GitHub-Packages-only package (site-generator,
checkout-*) must stay on marketing-site: npm scopes a registry per scope,
not per package, so one repo cannot draw @flowmatrix-ai/site-components from
npmjs and @flowmatrix-ai/checkout-ui from GitHub Packages.
@flowmatrix-ai/brand used to be on that list. It went public on 2026-08-31, so
the three FlowMatrix-owned properties that depend on it — site-flowmatrixai-main,
site-flowmatrixai-studio and flowmatrixai-org — are no longer pinned to
GitHub Packages by it.
Usage:
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": ["local>FlowMatrix-AI/renovate-config:site-npmjs"]
}Renovate on this org has two independent switches, and a repo gets PRs only when both are on:
- The GitHub App installation. It is installed org-wide with access to all
repositories, so every repo is already in scope. Check it with
gh api /orgs/FlowMatrix-AI/installations. - Per-repo activation in the Mend portal
(
developer.mend.io/github/FlowMatrix-AI/<repo>→ Dependency Updates (Renovate)):Disabled,SilentorInteractive. It is not visible from the GitHub API. A new repo must be set toInteractive.Silentruns lookups and fills the dashboard but opens no PRs.
So "Renovate isn't running here" is usually the second switch, not a permissions problem. Judge it from the repo, not from the portal's status text, which has shown states the repo contradicted. A repo where Renovate is really active has all three of:
- one or more
renovate/*branches - a
Dependency Dashboardissue authored byapp/renovate - Renovate-authored PRs
Absent all three: the portal switch is off. A dashboard issue with no PRs:
Silent. Present but stale: a config or schedule problem. The first run after
activation ignores the preset's schedule, so PRs can appear within minutes.
The presets above set automerge: true on low-risk update types, but that only
takes effect if the repository setting "Allow auto-merge" is enabled.
Renovate uses GitHub platform automerge by default, which silently no-ops
when the repo setting is off — PRs then sit open until merged by hand (this is
exactly what stranded the sites fleet's pin/patch PRs).
Enable it per repo:
gh api -X PATCH repos/FlowMatrix-AI/<repo> -F allow_auto_merge=trueIt is safe: auto-merge still fires only when the required checks (ok +
gitleaks / gitleaks) pass, branch protection is unchanged, and only renovate
PRs the presets mark automerge: true (non-major pins/digests/patches)
self-merge. The sites/marketing fleet (tier=sites + site-platform) has it
on; the drift-audit flags any fleet repo where it regresses (auto-merge-off).
The npmrc entry in default.json points the @flowmatrix-ai scope at
npm.pkg.github.com; the Renovate GitHub App's auto-provisioned installation
token is used for lookups. (An empty hostRules entry was removed in
52d8074
because it clobbered that auto-provisioned token.) If the App token lacks
packages:read, add an encrypted PAT via
Renovate's encryption endpoint under a
hostRules entry.
npmrc is not only a lookup setting. It is also what Renovate hands to
npm/pnpm when it regenerates a lockfile, so it decides the resolved URLs
that get committed. The registryUrls packageRule for the three
@flowmatrix-ai/site-* packages governs lookup only and does not change
what lands in the lock. That is why a migrated site needs the site-npmjs
preset rather than the packageRule alone.