From 7874ce7d5118ce8ab63d0231ff63f260ef0b37c8 Mon Sep 17 00:00:00 2001 From: Benjamin Pracht Date: Wed, 16 Sep 2026 20:45:20 -0700 Subject: [PATCH] Track action versions and stop quarantining our own actions (#4877) helpers:pinGitHubActionDigestsToSemver extends the preset we already used, so actions stay pinned by digest; it adds an extractVersion/versioning pair that makes Renovate follow the full vX.Y.Z tag behind the digest instead of the mutable major, so the comment a reviewer reads carries the exact version and updates arrive typed as patch/minor with a changelog range. minimumReleaseAge exists to let a third-party release sit before we adopt it. Our own actions have nothing to wait out, and the quarantine actively hurts any referenced by branch: Renovate ages a branch ref against its head commit, so slack-notifier-action only moves once that repo goes two weeks without a push. This mirrors the exemption github.com/livekit/** already has under gomod. Co-authored-by: Claude Opus 5 --- renovate.json | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/renovate.json b/renovate.json index f2106f3b1..efd16dc9f 100644 --- a/renovate.json +++ b/renovate.json @@ -2,7 +2,7 @@ "$schema": "https://docs.renovatebot.com/renovate-schema.json", "extends": [ "config:recommended", - "helpers:pinGitHubActionDigests" + "helpers:pinGitHubActionDigestsToSemver" ], "minimumReleaseAge": "2 weeks", "commitBody": "Generated by renovateBot", @@ -19,6 +19,14 @@ "matchManagers": ["github-actions"], "groupName": "github workflows" }, + { + "description": "First-party actions, no need to quarantine: we own them, and one referenced by branch would otherwise sit pending until its default branch goes two weeks without a commit", + "matchManagers": ["github-actions"], + "matchPackageNames": [ + "livekit/**" + ], + "minimumReleaseAge": null + }, { "matchManagers": ["dockerfile"], "groupName": "docker deps",