Track action versions and stop quarantining our own actions (#4877)

helpers:pinGitHubActionDigestsToSemver extends the preset we already used, so
actions stay pinned by digest; it adds an extractVersion/versioning pair that
makes Renovate follow the full vX.Y.Z tag behind the digest instead of the
mutable major, so the comment a reviewer reads carries the exact version and
updates arrive typed as patch/minor with a changelog range.

minimumReleaseAge exists to let a third-party release sit before we adopt it.
Our own actions have nothing to wait out, and the quarantine actively hurts any
referenced by branch: Renovate ages a branch ref against its head commit, so
slack-notifier-action only moves once that repo goes two weeks without a push.
This mirrors the exemption github.com/livekit/** already has under gomod.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Benjamin Pracht
2026-09-16 20:45:20 -07:00
committed by GitHub
co-authored by Claude Opus 5
parent 48700da3f3
commit 7874ce7d51
+9 -1
View File
@@ -2,7 +2,7 @@
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": [
"config:recommended",
"helpers:pinGitHubActionDigests"
"helpers:pinGitHubActionDigestsToSemver"
],
"minimumReleaseAge": "2 weeks",
"commitBody": "Generated by renovateBot",
@@ -19,6 +19,14 @@
"matchManagers": ["github-actions"],
"groupName": "github workflows"
},
{
"description": "First-party actions, no need to quarantine: we own them, and one referenced by branch would otherwise sit pending until its default branch goes two weeks without a commit",
"matchManagers": ["github-actions"],
"matchPackageNames": [
"livekit/**"
],
"minimumReleaseAge": null
},
{
"matchManagers": ["dockerfile"],
"groupName": "docker deps",