Skip to content

SCANDOCKER-89 Add Renovate configuration - #322

Merged
alban-auzeill merged 2 commits into
masterfrom
alban/SCANDOCKER-89
Sep 17, 2026
Merged

alban-auzeill merged 2 commits into
masterfrom
alban/SCANDOCKER-89

Conversation

@alban-auzeill

@alban-auzeill alban-auzeill commented Sep 16, 2026 •

Copy link
Copy Markdown
Member

Summary by Gitar

  • Configuration:
    • Added renovate.json configuration file with custom package rules for amazoncorretto

This will update automatically on new commits.

@alban-auzeill
alban-auzeill requested a review from a team as a code owner September 16, 2026 06:33
@hashicorp-vault-sonar-prod

Copy link
Copy Markdown

SCANDOCKER-89

@alban-auzeill
alban-auzeill requested review from antoine-vinot-sonarsource and removed request for a team September 16, 2026 07:19
Comment thread renovate.json Outdated
Comment thread renovate.json Outdated
@gitar-bot

gitar-bot Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Code Review ✅ Approved 1 closed / 1 findings

Adds Renovate configuration for automated dependency updates. A rule description issue regarding minor Corretto updates has been resolved.

✅ 1 closed
✅ Quality: Rule description promises minor Corretto updates that cannot happen

📄 renovate.json:8 📄 renovate.json:12-17 🔗 version precision
The Dockerfile pins the base image as FROM amazoncorretto:21-al2023, and Renovate preserves the version precision of the existing tag (per the Docker versioning docs), so it will only ever propose major bumps such as 22-al2023 — never a minor/patch tag like 21.0.9-al2023. The new description therefore states a behavior ("Update the Corretto Java minor version") that this configuration and tag form cannot produce, and it drops the previous, accurate explanation that JDK patch and Amazon Linux errata arrive through upstream refreshes of the 21-al2023 tag at build time. Restore that rationale in the description so a future maintainer does not assume Renovate is tracking Java minor releases.

Review coverage

Functional validation 1 of 1 objectives covered

Rules No rules evaluated

Auto-approval Not enabled · Set up

Implementation Status ✅ 1 of 1 objectives covered
✅ SCANDOCKER-89 - 1 of 1 objectives covered

This PR adds the Renovate configuration file as requested.

✅ 1 covered here
  • ✅ Add Renovate configuration
Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Counting what did not apply, without listing it.

Comment with these commands to change the behavior for this request:

Auto-apply Compact
gitar auto-apply:on         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

@sonarqube-next

Copy link
Copy Markdown

Quality Gate passed Quality Gate passed

Issues
0 New issues
0 Fixed issues
0 Accepted issues

Measures
0 Security Hotspots
0 Dependency risks
No data about Coverage
No data about Duplication

See analysis details on SonarQube

@alban-auzeill
alban-auzeill merged commit 887968f into master Sep 17, 2026
10 checks passed
@alban-auzeill
alban-auzeill deleted the alban/SCANDOCKER-89 branch September 17, 2026 09:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants