feat(renovate): scope the NUT feat: to minor/major bumps - #108
Merged
Merged
Conversation
renovatebot/renovate#45691 merged at 08:07 UTC on 2026-09-17 and 44.96.0 was cut at that commit (compare/44.96.0...9b87f8d is "identical"), so built-in `RUN apk add` extraction has been available since 44.96.0, not 44.97.1 as this rule's description claimed. Confirmed in production: the Mend-hosted runner extracted these pins on 44.96.3. Comment-only change; no behavior change.
owine/renovate-config now types no dependency update `feat:` — a `feat:`
commit is release-please's minor-bump trigger, and Renovate can't know
whether an upstream bump is visible to this repo's consumers.
This repo is the sanctioned exception, and the rule now says why: it's a
packaging shim whose entire output is NUT, built from source, so the
version a user runs IS this dependency's version. The question Renovate
can't normally answer ("is this bump consumer-visible?") has a fixed
answer of yes.
Scoped to minor/major so an upstream PATCH stays `deps:` (patch release)
instead of cutting a minor here — the wrapper's semver now tracks
upstream's own update type rather than drifting a digit ahead of it.
Split into two rules so each property has one home: the gate rule
(`nut source` group, `automerge: false`, `needs-review`) covers every
update type and sets no commit type; the `feat:` rule sets no automerge.
Building from source means a patch bump is still a rebuild worth reading,
so the review gate deliberately stays wider than the `feat:`.
Reviewer's guide (collapsed on small PRs)Reviewer's GuideUpdates the Renovate configuration so NUT patch bumps use the fleet’s File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Depends on owine/renovate-config#101, which stops the shared presets from ever typing a dependency update
feat:.What
feat:→ minor releasedeps:→ patch releasefeat:→ minor releasefeat:→ minor releaseneeds-review)Why this repo keeps a
feat:at allThe fleet rule is now that no dependency update is ever typed
feat:— that commit is release-please's minor-bump trigger, and the minor digit is the repo's promise to its consumers, which Renovate can't make on your behalf.This repo is the sanctioned exception, and the rule's description now says so explicitly: it's a packaging shim whose entire output is NUT, built from source. The version a user runs is this dependency's version, so the question Renovate normally can't answer — "is this bump consumer-visible?" — has a fixed answer of yes, by construction.
Why minor/major only
An upstream NUT patch was cutting a minor release here, so the wrapper's version drifted a digit ahead of upstream's for no reason. Mirroring upstream's own update type keeps this repo's semver meaningful.
Shape
Split into two rules so each property has exactly one home:
nut sourcegroup,automerge: false,needs-review) covers every update type and sets no commit type, inheriting the fleet'sdeps:baseline;feat:rule sets no automerge.The review gate stays deliberately wider than the
feat:— building from source means even a patch bump is a rebuild worth reading before it lands.Not
feat!:on a major: an upstream major is not automatically breaking for this image's users.Verification
renovate-config-validator .github/renovate.json→ "Config validated successfully".Note: this branch also carries the previously-unpushed local commit 27e6705 (
docs(renovate): correct the apk-extraction version floor to 44.96.0), which touches the same file.Summary by Sourcery
Align NUT dependency commit types with upstream update severity while preserving review requirements for source-built releases.
Enhancements:
feat:type, while patch bumps retain the standard dependency type.