chore: initialize from backend template 0a6dd0e
This commit is contained in:
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
||||
"description": [
|
||||
"feature-dependency-vulnerability-management-contract D6 / §4 — dependency SECURITY update automation.",
|
||||
"Renovate is primary over Dependabot: with a gradle/libs.versions.toml version catalog plus Gradle",
|
||||
"lockfiles, Dependabot does not refresh the lockfile (issue #12557), which conflicts with",
|
||||
"feature-build-release-supply-chain-contract D8 (dependency locking). Dependabot stays a conditional",
|
||||
"alternative for forks that standardize on it or do not use lockfiles.",
|
||||
"Transitive vulnerabilities are NOT covered by either bot (direct deps only) — pin them with a Gradle",
|
||||
"dependency constraint / resolutionStrategy.force (§4) and regenerate locks (supply-chain D8)."
|
||||
],
|
||||
"extends": [
|
||||
"config:recommended",
|
||||
"security:only-security-updates"
|
||||
],
|
||||
"vulnerabilityAlerts": {
|
||||
"description": "Stable GitHub vulnerability alerts → immediate security PR, ignoring schedule.",
|
||||
"enabled": true,
|
||||
"labels": ["security", "dependencies"]
|
||||
},
|
||||
"osvVulnerabilityAlerts": true,
|
||||
"packageRules": [
|
||||
{
|
||||
"description": "UNSUPPORTED_IMPL_DECISION (team-policy): auto-merge patch-level security updates once CI is green — lowest breaking risk. Requires trustworthy CI coverage; a fork with weak CI should set this to false.",
|
||||
"matchUpdateTypes": ["patch", "pin", "digest"],
|
||||
"automerge": true,
|
||||
"automergeType": "pr"
|
||||
},
|
||||
{
|
||||
"description": "minor/major security updates require human review (breaking-change risk).",
|
||||
"matchUpdateTypes": ["minor", "major"],
|
||||
"automerge": false
|
||||
}
|
||||
]
|
||||
}
|
||||
Reference in New Issue
Block a user