chore(deps): activate organization Renovate preset - #352
Conversation
|
Agent handoff — hosted Renovate validation is not arriving.
Inference: Renovate is not currently processing this repository. Keep this PR draft and keep Dependabot unchanged. Resume after Renovate is re-enabled/re-onboarded (or a trusted local validator is explicitly authorized), then revalidate this head before merge. Tracker detail: z-shell/.github#452 |
There was a problem hiding this comment.
Pull request overview
Activates the shared Renovate configuration while retaining Dependabot security ownership and Stage 1 safeguards.
Changes:
- Extends the organization Renovate preset.
- Requires dashboard approval and disables vulnerability remediation.
- Targets dependency updates to
next.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| @@ -0,0 +1,9 @@ | |||
| { | |||
Summary
local>z-shell/.github:renovate-configpreset from the default branchnextwithbaseBranchPatterns.github/dependabot.ymlunchanged until live Renovate processing and GitHub security settings are verifiedSafety boundary
This is Stage 1 of z-shell/.github#452. Do not approve any Dependency Dashboard update while this gate is active. Stage 2 will remove routine Dependabot configuration and the dashboard-approval gate atomically only after the tracker’s live-processing, security-settings, and zero-open-routine-Dependabot-PR gates pass.
Verification
jq empty renovate.json: passgit diff --check: passrenovate/reconfigurepoints at this exact head; pass/fail status pendingDraft until hosted Renovate validation and the remaining repository-security gates are satisfied.
Tracks: z-shell/.github#452