Skip to content

SRE-1092: Update renovate - #111

Closed
TimDiekmann wants to merge 1 commit into
mainfrom
t/sre-1092-update-renovate-vulnerabilities
Closed

TimDiekmann wants to merge 1 commit into
mainfrom
t/sre-1092-update-renovate-vulnerabilities

Conversation

@TimDiekmann

@TimDiekmann TimDiekmann commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

The shared install-renovate action now pins renovate 44.101.2 instead of 44.34.3. This change updates package.json and package-lock.json.

Linear: SRE-1092

Checks:

  • git diff --check passed.
  • npm ci --dry-run --ignore-scripts --no-audit --no-fund passed.
  • A full npm ci could not complete because the local environment could not resolve registry.npmjs.org.

@TimDiekmann TimDiekmann self-assigned this Sep 25, 2026
@TimDiekmann
TimDiekmann marked this pull request as ready for review September 25, 2026 16:38
@TimDiekmann
TimDiekmann requested review from CiaranMn and a lite review from Copilot September 25, 2026 16:38

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@cursor

cursor Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
Changes only the GitHub Action’s dev dependency pin for Renovate; runtime product code is unaffected, though Renovate behavior in housekeeping workflows may shift with the large version jump.

Overview
Bumps the centrally pinned Renovate dev dependency in .github/actions/install-renovate from 44.34.3 to 44.101.2, with the lockfile refreshed so CI workflows that use this composite action install the new tree via npm ci.

The lockfile update also pulls in patched js-yaml (4.3.2) and adm-zip (0.6.1) to address the cited advisories, along with Renovate’s own dependency churn (e.g. AWS SDK, OpenTelemetry exporters including OTLP gRPC, got 16, Azure DevOps API 17, google-auth-library 11, @redis/client 6, markdown-it 15).

Reviewed by Cursor Bugbot for commit 8aa27d5. Bugbot is set up for automated code reviews on this repo. Configure here.

@TimDiekmann TimDiekmann changed the title SRE-1092: Update renovate to fix js-yaml and adm-zip vulnerabilities SRE-1092: Update renovate Sep 25, 2026
auto-merge was automatically disabled September 26, 2026 16:16

Pull request was closed

@TimDiekmann
TimDiekmann deleted the t/sre-1092-update-renovate-vulnerabilities branch September 26, 2026 16:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants