ci(renovate): add scheduled Renovate workflow - #460

Merged
OisinKyne merged 4 commits into
mainfrom
chore/add-renovate-workflow
May 11, 2026
Merged

ci(renovate): add scheduled Renovate workflow#460
OisinKyne merged 4 commits into
mainfrom
chore/add-renovate-workflow

Conversation

@bussyjd

@bussyjdbussyjd commented May 11, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adds .github/workflows/renovate.yml — hourly scheduled Renovate run plus a workflow_dispatch trigger with a dry_run input
  • This workflow was originally introduced in the integration branch behind Review of my sell agent work so far #455 but dropped during the squash merge to main. The existing renovate.json config currently has no runner without it

Test plan

  • Confirmed via gh api repos/.../actions/secrets: RENOVATE_TOKEN is NOT yet configured. Repo has only ANTHROPIC_API_KEY, GOOGLE_API_KEY, HOODI_FUNDER_PRIVATE_KEY. See comment thread — needs either a PAT secret added before merge, or a swap to GITHUB_TOKEN + pull-requests: write permission
  • Once secret resolved + merged, trigger via Actions → Renovate → Run workflow with dry_run=true and verify the run completes without opening PRs
  • Confirm the next hourly schedule fires and Renovate processes the existing renovate.json managers (frontend tag, gateway API version, image pins)

Adds an hourly scheduled Renovate workflow plus manual workflow_dispatch
trigger. This workflow was introduced in the integration branch behind
PR #455 but dropped during the squash merge to main; the existing
renovate.json config has no runner without it.
Requires the RENOVATE_TOKEN secret to be configured on the repository.
Comment thread.github/workflows/renovate.yml Fixed
@OisinKyne

OisinKyne commented May 11, 2026

Copy link
Copy Markdown
Contributor

please confirm whether dropping the workflow file from #455 was intentional (e.g. you're relying on the hosted Mend Renovate GitHub App).

No, deleting renovate maybe wasn't intentional? i see no deletions in that pr? it adds a renovate file? but maybe we're supposed to use github built in renovate not a third party renovate bot, idk. I just wanted pr bumps for more version checking.

https://github.com/ObolNetwork/obol-stack/pull/455/changes#diff-2f2dcee4f3f279ea8d2f4cd0235f2ab917d8cf1d8e11f4f195a3816afe79af26R1

@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Quick clarification on the timeline so this isn't ambiguous:

So this PR re-adds what got lost during the squash, nothing more. Independent of the hosted-vs-self-hosted question — renovate.json config currently has nothing to actually run it because no Renovate Action lives in .github/workflows/. If we later prefer the Mend GitHub App route, we can swap by uninstalling this workflow and installing the App; the config file stays the same.

If you're happy, I'll merge once #460 has a tick.

@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Heads-up from running through the test plan: RENOVATE_TOKEN does not currently exist in the repo's Actions secrets (only ANTHROPIC_API_KEY, GOOGLE_API_KEY, HOODI_FUNDER_PRIVATE_KEY). The workflow as written will fail on first run.

Two options:

  1. Add the secret before merging. Renovate's Action wants a PAT with repo + workflow scopes, or a fine-grained PAT scoped to this repo with Contents: write, Pull requests: write, Actions: read. Generate one under a dedicated service identity and add it as RENOVATE_TOKEN.
  2. Drop the secret reference and use GITHUB_TOKEN. Works fine for opening PRs in the same repo; the only catch is PRs opened by GITHUB_TOKEN don't trigger other workflows on the resulting PRs (so CI wouldn't auto-run on Renovate PRs unless you swap in a PAT for that purpose).

Happy to push option 2 onto this branch if you'd prefer to avoid the secret management overhead.

@OisinKyne

Copy link
Copy Markdown
Contributor

push option 2?

OisinKyneand others added 2 commits May 11, 2026 13:24
Per review feedback. The repo doesn't currently have a RENOVATE_TOKEN
secret configured; switching to the workflow-scoped GITHUB_TOKEN avoids
the need to mint and rotate a personal access token.
Adds an explicit permissions block so the workflow can:
- write contents: create the renovate/* branches it commits updates to
- write pull-requests: open the PRs themselves
- write issues: maintain Renovate's onboarding/dependency-dashboard issue
Trade-off vs a PAT: PRs opened by GITHUB_TOKEN do not trigger downstream
workflows (so CI checks won't auto-run on Renovate's PRs). If we later
want CI on Renovate PRs we can swap back to a fine-grained PAT.
@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Pushed option 2 in f6852ec: swapped to secrets.GITHUB_TOKEN and added an explicit permissions block (contents: write for the renovate/* branches, pull-requests: write for opening PRs, issues: write for the Dependency Dashboard / onboarding issue).

Trade-off worth flagging: GitHub does not run downstream workflows on PRs opened by GITHUB_TOKEN. So Renovate's PRs won't auto-trigger lint-test etc. until someone closes/reopens them or pushes a commit. If that becomes annoying we can revisit with a fine-grained PAT later.

Comment thread.github/workflows/renovate.yml Outdated
Signed-off-by: Oisín Kyne <4981644+OisinKyne@users.noreply.github.com>
@OisinKyne
OisinKyne merged commit b13254e into mainMay 11, 2026
6 checks passed
@OisinKyne
OisinKyne deleted the chore/add-renovate-workflow branch May 11, 2026 12:33
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@bussyjd@OisinKyne@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
Skip to content

ci(renovate): add scheduled Renovate workflow - #460

Merged
OisinKyne merged 4 commits into
mainfrom
chore/add-renovate-workflow
May 11, 2026
Merged

ci(renovate): add scheduled Renovate workflow#460
OisinKyne merged 4 commits into
mainfrom
chore/add-renovate-workflow

Conversation

@bussyjd

@bussyjdbussyjd commented May 11, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adds .github/workflows/renovate.yml — hourly scheduled Renovate run plus a workflow_dispatch trigger with a dry_run input
  • This workflow was originally introduced in the integration branch behind Review of my sell agent work so far #455 but dropped during the squash merge to main. The existing renovate.json config currently has no runner without it

Test plan

  • Confirmed via gh api repos/.../actions/secrets: RENOVATE_TOKEN is NOT yet configured. Repo has only ANTHROPIC_API_KEY, GOOGLE_API_KEY, HOODI_FUNDER_PRIVATE_KEY. See comment thread — needs either a PAT secret added before merge, or a swap to GITHUB_TOKEN + pull-requests: write permission
  • Once secret resolved + merged, trigger via Actions → Renovate → Run workflow with dry_run=true and verify the run completes without opening PRs
  • Confirm the next hourly schedule fires and Renovate processes the existing renovate.json managers (frontend tag, gateway API version, image pins)

Adds an hourly scheduled Renovate workflow plus manual workflow_dispatch
trigger. This workflow was introduced in the integration branch behind
PR #455 but dropped during the squash merge to main; the existing
renovate.json config has no runner without it.
Requires the RENOVATE_TOKEN secret to be configured on the repository.
Comment thread.github/workflows/renovate.yml Fixed
@OisinKyne

OisinKyne commented May 11, 2026

Copy link
Copy Markdown
Contributor

please confirm whether dropping the workflow file from #455 was intentional (e.g. you're relying on the hosted Mend Renovate GitHub App).

No, deleting renovate maybe wasn't intentional? i see no deletions in that pr? it adds a renovate file? but maybe we're supposed to use github built in renovate not a third party renovate bot, idk. I just wanted pr bumps for more version checking.

https://github.com/ObolNetwork/obol-stack/pull/455/changes#diff-2f2dcee4f3f279ea8d2f4cd0235f2ab917d8cf1d8e11f4f195a3816afe79af26R1

@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Quick clarification on the timeline so this isn't ambiguous:

So this PR re-adds what got lost during the squash, nothing more. Independent of the hosted-vs-self-hosted question — renovate.json config currently has nothing to actually run it because no Renovate Action lives in .github/workflows/. If we later prefer the Mend GitHub App route, we can swap by uninstalling this workflow and installing the App; the config file stays the same.

If you're happy, I'll merge once #460 has a tick.

@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Heads-up from running through the test plan: RENOVATE_TOKEN does not currently exist in the repo's Actions secrets (only ANTHROPIC_API_KEY, GOOGLE_API_KEY, HOODI_FUNDER_PRIVATE_KEY). The workflow as written will fail on first run.

Two options:

  1. Add the secret before merging. Renovate's Action wants a PAT with repo + workflow scopes, or a fine-grained PAT scoped to this repo with Contents: write, Pull requests: write, Actions: read. Generate one under a dedicated service identity and add it as RENOVATE_TOKEN.
  2. Drop the secret reference and use GITHUB_TOKEN. Works fine for opening PRs in the same repo; the only catch is PRs opened by GITHUB_TOKEN don't trigger other workflows on the resulting PRs (so CI wouldn't auto-run on Renovate PRs unless you swap in a PAT for that purpose).

Happy to push option 2 onto this branch if you'd prefer to avoid the secret management overhead.

@OisinKyne

Copy link
Copy Markdown
Contributor

push option 2?

OisinKyneand others added 2 commits May 11, 2026 13:24
Per review feedback. The repo doesn't currently have a RENOVATE_TOKEN
secret configured; switching to the workflow-scoped GITHUB_TOKEN avoids
the need to mint and rotate a personal access token.
Adds an explicit permissions block so the workflow can:
- write contents: create the renovate/* branches it commits updates to
- write pull-requests: open the PRs themselves
- write issues: maintain Renovate's onboarding/dependency-dashboard issue
Trade-off vs a PAT: PRs opened by GITHUB_TOKEN do not trigger downstream
workflows (so CI checks won't auto-run on Renovate's PRs). If we later
want CI on Renovate PRs we can swap back to a fine-grained PAT.
@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Pushed option 2 in f6852ec: swapped to secrets.GITHUB_TOKEN and added an explicit permissions block (contents: write for the renovate/* branches, pull-requests: write for opening PRs, issues: write for the Dependency Dashboard / onboarding issue).

Trade-off worth flagging: GitHub does not run downstream workflows on PRs opened by GITHUB_TOKEN. So Renovate's PRs won't auto-trigger lint-test etc. until someone closes/reopens them or pushes a commit. If that becomes annoying we can revisit with a fine-grained PAT later.

Comment thread.github/workflows/renovate.yml Outdated
Signed-off-by: Oisín Kyne <4981644+OisinKyne@users.noreply.github.com>
@OisinKyne
OisinKyne merged commit b13254e into mainMay 11, 2026
6 checks passed
@OisinKyne
OisinKyne deleted the chore/add-renovate-workflow branch May 11, 2026 12:33
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@bussyjd@OisinKyne@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci(renovate): add scheduled Renovate workflow - #460

Merged
OisinKyne merged 4 commits into
mainfrom
chore/add-renovate-workflow
May 11, 2026
Merged

ci(renovate): add scheduled Renovate workflow#460
OisinKyne merged 4 commits into
mainfrom
chore/add-renovate-workflow

Conversation

@bussyjd

@bussyjdbussyjd commented May 11, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adds .github/workflows/renovate.yml — hourly scheduled Renovate run plus a workflow_dispatch trigger with a dry_run input
  • This workflow was originally introduced in the integration branch behind Review of my sell agent work so far #455 but dropped during the squash merge to main. The existing renovate.json config currently has no runner without it

Test plan

  • Confirmed via gh api repos/.../actions/secrets: RENOVATE_TOKEN is NOT yet configured. Repo has only ANTHROPIC_API_KEY, GOOGLE_API_KEY, HOODI_FUNDER_PRIVATE_KEY. See comment thread — needs either a PAT secret added before merge, or a swap to GITHUB_TOKEN + pull-requests: write permission
  • Once secret resolved + merged, trigger via Actions → Renovate → Run workflow with dry_run=true and verify the run completes without opening PRs
  • Confirm the next hourly schedule fires and Renovate processes the existing renovate.json managers (frontend tag, gateway API version, image pins)

Adds an hourly scheduled Renovate workflow plus manual workflow_dispatch
trigger. This workflow was introduced in the integration branch behind
PR #455 but dropped during the squash merge to main; the existing
renovate.json config has no runner without it.
Requires the RENOVATE_TOKEN secret to be configured on the repository.
Comment thread.github/workflows/renovate.yml Fixed
@OisinKyne

OisinKyne commented May 11, 2026

Copy link
Copy Markdown
Contributor

please confirm whether dropping the workflow file from #455 was intentional (e.g. you're relying on the hosted Mend Renovate GitHub App).

No, deleting renovate maybe wasn't intentional? i see no deletions in that pr? it adds a renovate file? but maybe we're supposed to use github built in renovate not a third party renovate bot, idk. I just wanted pr bumps for more version checking.

https://github.com/ObolNetwork/obol-stack/pull/455/changes#diff-2f2dcee4f3f279ea8d2f4cd0235f2ab917d8cf1d8e11f4f195a3816afe79af26R1

@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Quick clarification on the timeline so this isn't ambiguous:

So this PR re-adds what got lost during the squash, nothing more. Independent of the hosted-vs-self-hosted question — renovate.json config currently has nothing to actually run it because no Renovate Action lives in .github/workflows/. If we later prefer the Mend GitHub App route, we can swap by uninstalling this workflow and installing the App; the config file stays the same.

If you're happy, I'll merge once #460 has a tick.

@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Heads-up from running through the test plan: RENOVATE_TOKEN does not currently exist in the repo's Actions secrets (only ANTHROPIC_API_KEY, GOOGLE_API_KEY, HOODI_FUNDER_PRIVATE_KEY). The workflow as written will fail on first run.

Two options:

  1. Add the secret before merging. Renovate's Action wants a PAT with repo + workflow scopes, or a fine-grained PAT scoped to this repo with Contents: write, Pull requests: write, Actions: read. Generate one under a dedicated service identity and add it as RENOVATE_TOKEN.
  2. Drop the secret reference and use GITHUB_TOKEN. Works fine for opening PRs in the same repo; the only catch is PRs opened by GITHUB_TOKEN don't trigger other workflows on the resulting PRs (so CI wouldn't auto-run on Renovate PRs unless you swap in a PAT for that purpose).

Happy to push option 2 onto this branch if you'd prefer to avoid the secret management overhead.

@OisinKyne

Copy link
Copy Markdown
Contributor

push option 2?

OisinKyneand others added 2 commits May 11, 2026 13:24
Per review feedback. The repo doesn't currently have a RENOVATE_TOKEN
secret configured; switching to the workflow-scoped GITHUB_TOKEN avoids
the need to mint and rotate a personal access token.
Adds an explicit permissions block so the workflow can:
- write contents: create the renovate/* branches it commits updates to
- write pull-requests: open the PRs themselves
- write issues: maintain Renovate's onboarding/dependency-dashboard issue
Trade-off vs a PAT: PRs opened by GITHUB_TOKEN do not trigger downstream
workflows (so CI checks won't auto-run on Renovate's PRs). If we later
want CI on Renovate PRs we can swap back to a fine-grained PAT.
@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Pushed option 2 in f6852ec: swapped to secrets.GITHUB_TOKEN and added an explicit permissions block (contents: write for the renovate/* branches, pull-requests: write for opening PRs, issues: write for the Dependency Dashboard / onboarding issue).

Trade-off worth flagging: GitHub does not run downstream workflows on PRs opened by GITHUB_TOKEN. So Renovate's PRs won't auto-trigger lint-test etc. until someone closes/reopens them or pushes a commit. If that becomes annoying we can revisit with a fine-grained PAT later.

Comment thread.github/workflows/renovate.yml Outdated
Signed-off-by: Oisín Kyne <4981644+OisinKyne@users.noreply.github.com>
@OisinKyne
OisinKyne merged commit b13254e into mainMay 11, 2026
6 checks passed
@OisinKyne
OisinKyne deleted the chore/add-renovate-workflow branch May 11, 2026 12:33
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@bussyjd@OisinKyne@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci(renovate): add scheduled Renovate workflow - #460

Merged
OisinKyne merged 4 commits into
mainfrom
chore/add-renovate-workflow
May 11, 2026
Merged

ci(renovate): add scheduled Renovate workflow#460
OisinKyne merged 4 commits into
mainfrom
chore/add-renovate-workflow

Conversation

@bussyjd

@bussyjdbussyjd commented May 11, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adds .github/workflows/renovate.yml — hourly scheduled Renovate run plus a workflow_dispatch trigger with a dry_run input
  • This workflow was originally introduced in the integration branch behind Review of my sell agent work so far #455 but dropped during the squash merge to main. The existing renovate.json config currently has no runner without it

Test plan

  • Confirmed via gh api repos/.../actions/secrets: RENOVATE_TOKEN is NOT yet configured. Repo has only ANTHROPIC_API_KEY, GOOGLE_API_KEY, HOODI_FUNDER_PRIVATE_KEY. See comment thread — needs either a PAT secret added before merge, or a swap to GITHUB_TOKEN + pull-requests: write permission
  • Once secret resolved + merged, trigger via Actions → Renovate → Run workflow with dry_run=true and verify the run completes without opening PRs
  • Confirm the next hourly schedule fires and Renovate processes the existing renovate.json managers (frontend tag, gateway API version, image pins)

Adds an hourly scheduled Renovate workflow plus manual workflow_dispatch
trigger. This workflow was introduced in the integration branch behind
PR #455 but dropped during the squash merge to main; the existing
renovate.json config has no runner without it.
Requires the RENOVATE_TOKEN secret to be configured on the repository.
Comment thread.github/workflows/renovate.yml Fixed
@OisinKyne

OisinKyne commented May 11, 2026

Copy link
Copy Markdown
Contributor

please confirm whether dropping the workflow file from #455 was intentional (e.g. you're relying on the hosted Mend Renovate GitHub App).

No, deleting renovate maybe wasn't intentional? i see no deletions in that pr? it adds a renovate file? but maybe we're supposed to use github built in renovate not a third party renovate bot, idk. I just wanted pr bumps for more version checking.

https://github.com/ObolNetwork/obol-stack/pull/455/changes#diff-2f2dcee4f3f279ea8d2f4cd0235f2ab917d8cf1d8e11f4f195a3816afe79af26R1

@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Quick clarification on the timeline so this isn't ambiguous:

So this PR re-adds what got lost during the squash, nothing more. Independent of the hosted-vs-self-hosted question — renovate.json config currently has nothing to actually run it because no Renovate Action lives in .github/workflows/. If we later prefer the Mend GitHub App route, we can swap by uninstalling this workflow and installing the App; the config file stays the same.

If you're happy, I'll merge once #460 has a tick.

@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Heads-up from running through the test plan: RENOVATE_TOKEN does not currently exist in the repo's Actions secrets (only ANTHROPIC_API_KEY, GOOGLE_API_KEY, HOODI_FUNDER_PRIVATE_KEY). The workflow as written will fail on first run.

Two options:

  1. Add the secret before merging. Renovate's Action wants a PAT with repo + workflow scopes, or a fine-grained PAT scoped to this repo with Contents: write, Pull requests: write, Actions: read. Generate one under a dedicated service identity and add it as RENOVATE_TOKEN.
  2. Drop the secret reference and use GITHUB_TOKEN. Works fine for opening PRs in the same repo; the only catch is PRs opened by GITHUB_TOKEN don't trigger other workflows on the resulting PRs (so CI wouldn't auto-run on Renovate PRs unless you swap in a PAT for that purpose).

Happy to push option 2 onto this branch if you'd prefer to avoid the secret management overhead.

@OisinKyne

Copy link
Copy Markdown
Contributor

push option 2?

OisinKyneand others added 2 commits May 11, 2026 13:24
Per review feedback. The repo doesn't currently have a RENOVATE_TOKEN
secret configured; switching to the workflow-scoped GITHUB_TOKEN avoids
the need to mint and rotate a personal access token.
Adds an explicit permissions block so the workflow can:
- write contents: create the renovate/* branches it commits updates to
- write pull-requests: open the PRs themselves
- write issues: maintain Renovate's onboarding/dependency-dashboard issue
Trade-off vs a PAT: PRs opened by GITHUB_TOKEN do not trigger downstream
workflows (so CI checks won't auto-run on Renovate's PRs). If we later
want CI on Renovate PRs we can swap back to a fine-grained PAT.
@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Pushed option 2 in f6852ec: swapped to secrets.GITHUB_TOKEN and added an explicit permissions block (contents: write for the renovate/* branches, pull-requests: write for opening PRs, issues: write for the Dependency Dashboard / onboarding issue).

Trade-off worth flagging: GitHub does not run downstream workflows on PRs opened by GITHUB_TOKEN. So Renovate's PRs won't auto-trigger lint-test etc. until someone closes/reopens them or pushes a commit. If that becomes annoying we can revisit with a fine-grained PAT later.

Comment thread.github/workflows/renovate.yml Outdated
Signed-off-by: Oisín Kyne <4981644+OisinKyne@users.noreply.github.com>
@OisinKyne
OisinKyne merged commit b13254e into mainMay 11, 2026
6 checks passed
@OisinKyne
OisinKyne deleted the chore/add-renovate-workflow branch May 11, 2026 12:33
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@bussyjd@OisinKyne@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

ci(renovate): add scheduled Renovate workflow - #460

Merged
OisinKyne merged 4 commits into
mainfrom
chore/add-renovate-workflow
May 11, 2026
Merged

ci(renovate): add scheduled Renovate workflow#460
OisinKyne merged 4 commits into
mainfrom
chore/add-renovate-workflow

Conversation

@bussyjd

@bussyjdbussyjd commented May 11, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adds .github/workflows/renovate.yml — hourly scheduled Renovate run plus a workflow_dispatch trigger with a dry_run input
  • This workflow was originally introduced in the integration branch behind Review of my sell agent work so far #455 but dropped during the squash merge to main. The existing renovate.json config currently has no runner without it

Test plan

  • Confirmed via gh api repos/.../actions/secrets: RENOVATE_TOKEN is NOT yet configured. Repo has only ANTHROPIC_API_KEY, GOOGLE_API_KEY, HOODI_FUNDER_PRIVATE_KEY. See comment thread — needs either a PAT secret added before merge, or a swap to GITHUB_TOKEN + pull-requests: write permission
  • Once secret resolved + merged, trigger via Actions → Renovate → Run workflow with dry_run=true and verify the run completes without opening PRs
  • Confirm the next hourly schedule fires and Renovate processes the existing renovate.json managers (frontend tag, gateway API version, image pins)

Adds an hourly scheduled Renovate workflow plus manual workflow_dispatch
trigger. This workflow was introduced in the integration branch behind
PR #455 but dropped during the squash merge to main; the existing
renovate.json config has no runner without it.
Requires the RENOVATE_TOKEN secret to be configured on the repository.
Comment thread.github/workflows/renovate.yml Fixed
@OisinKyne

OisinKyne commented May 11, 2026

Copy link
Copy Markdown
Contributor

please confirm whether dropping the workflow file from #455 was intentional (e.g. you're relying on the hosted Mend Renovate GitHub App).

No, deleting renovate maybe wasn't intentional? i see no deletions in that pr? it adds a renovate file? but maybe we're supposed to use github built in renovate not a third party renovate bot, idk. I just wanted pr bumps for more version checking.

https://github.com/ObolNetwork/obol-stack/pull/455/changes#diff-2f2dcee4f3f279ea8d2f4cd0235f2ab917d8cf1d8e11f4f195a3816afe79af26R1

@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Quick clarification on the timeline so this isn't ambiguous:

So this PR re-adds what got lost during the squash, nothing more. Independent of the hosted-vs-self-hosted question — renovate.json config currently has nothing to actually run it because no Renovate Action lives in .github/workflows/. If we later prefer the Mend GitHub App route, we can swap by uninstalling this workflow and installing the App; the config file stays the same.

If you're happy, I'll merge once #460 has a tick.

@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Heads-up from running through the test plan: RENOVATE_TOKEN does not currently exist in the repo's Actions secrets (only ANTHROPIC_API_KEY, GOOGLE_API_KEY, HOODI_FUNDER_PRIVATE_KEY). The workflow as written will fail on first run.

Two options:

  1. Add the secret before merging. Renovate's Action wants a PAT with repo + workflow scopes, or a fine-grained PAT scoped to this repo with Contents: write, Pull requests: write, Actions: read. Generate one under a dedicated service identity and add it as RENOVATE_TOKEN.
  2. Drop the secret reference and use GITHUB_TOKEN. Works fine for opening PRs in the same repo; the only catch is PRs opened by GITHUB_TOKEN don't trigger other workflows on the resulting PRs (so CI wouldn't auto-run on Renovate PRs unless you swap in a PAT for that purpose).

Happy to push option 2 onto this branch if you'd prefer to avoid the secret management overhead.

@OisinKyne

Copy link
Copy Markdown
Contributor

push option 2?

OisinKyneand others added 2 commits May 11, 2026 13:24
Per review feedback. The repo doesn't currently have a RENOVATE_TOKEN
secret configured; switching to the workflow-scoped GITHUB_TOKEN avoids
the need to mint and rotate a personal access token.
Adds an explicit permissions block so the workflow can:
- write contents: create the renovate/* branches it commits updates to
- write pull-requests: open the PRs themselves
- write issues: maintain Renovate's onboarding/dependency-dashboard issue
Trade-off vs a PAT: PRs opened by GITHUB_TOKEN do not trigger downstream
workflows (so CI checks won't auto-run on Renovate's PRs). If we later
want CI on Renovate PRs we can swap back to a fine-grained PAT.
@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Pushed option 2 in f6852ec: swapped to secrets.GITHUB_TOKEN and added an explicit permissions block (contents: write for the renovate/* branches, pull-requests: write for opening PRs, issues: write for the Dependency Dashboard / onboarding issue).

Trade-off worth flagging: GitHub does not run downstream workflows on PRs opened by GITHUB_TOKEN. So Renovate's PRs won't auto-trigger lint-test etc. until someone closes/reopens them or pushes a commit. If that becomes annoying we can revisit with a fine-grained PAT later.

Comment thread.github/workflows/renovate.yml Outdated
Signed-off-by: Oisín Kyne <4981644+OisinKyne@users.noreply.github.com>
@OisinKyne
OisinKyne merged commit b13254e into mainMay 11, 2026
6 checks passed
@OisinKyne
OisinKyne deleted the chore/add-renovate-workflow branch May 11, 2026 12:33
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@bussyjd@OisinKyne@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci(renovate): add scheduled Renovate workflow - #460

Merged
OisinKyne merged 4 commits into
mainfrom
chore/add-renovate-workflow
May 11, 2026
Merged

ci(renovate): add scheduled Renovate workflow#460
OisinKyne merged 4 commits into
mainfrom
chore/add-renovate-workflow

Conversation

@bussyjd

@bussyjdbussyjd commented May 11, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adds .github/workflows/renovate.yml — hourly scheduled Renovate run plus a workflow_dispatch trigger with a dry_run input
  • This workflow was originally introduced in the integration branch behind Review of my sell agent work so far #455 but dropped during the squash merge to main. The existing renovate.json config currently has no runner without it

Test plan

  • Confirmed via gh api repos/.../actions/secrets: RENOVATE_TOKEN is NOT yet configured. Repo has only ANTHROPIC_API_KEY, GOOGLE_API_KEY, HOODI_FUNDER_PRIVATE_KEY. See comment thread — needs either a PAT secret added before merge, or a swap to GITHUB_TOKEN + pull-requests: write permission
  • Once secret resolved + merged, trigger via Actions → Renovate → Run workflow with dry_run=true and verify the run completes without opening PRs
  • Confirm the next hourly schedule fires and Renovate processes the existing renovate.json managers (frontend tag, gateway API version, image pins)

Adds an hourly scheduled Renovate workflow plus manual workflow_dispatch
trigger. This workflow was introduced in the integration branch behind
PR #455 but dropped during the squash merge to main; the existing
renovate.json config has no runner without it.
Requires the RENOVATE_TOKEN secret to be configured on the repository.
Comment thread.github/workflows/renovate.yml Fixed
@OisinKyne

OisinKyne commented May 11, 2026

Copy link
Copy Markdown
Contributor

please confirm whether dropping the workflow file from #455 was intentional (e.g. you're relying on the hosted Mend Renovate GitHub App).

No, deleting renovate maybe wasn't intentional? i see no deletions in that pr? it adds a renovate file? but maybe we're supposed to use github built in renovate not a third party renovate bot, idk. I just wanted pr bumps for more version checking.

https://github.com/ObolNetwork/obol-stack/pull/455/changes#diff-2f2dcee4f3f279ea8d2f4cd0235f2ab917d8cf1d8e11f4f195a3816afe79af26R1

@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Quick clarification on the timeline so this isn't ambiguous:

So this PR re-adds what got lost during the squash, nothing more. Independent of the hosted-vs-self-hosted question — renovate.json config currently has nothing to actually run it because no Renovate Action lives in .github/workflows/. If we later prefer the Mend GitHub App route, we can swap by uninstalling this workflow and installing the App; the config file stays the same.

If you're happy, I'll merge once #460 has a tick.

@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Heads-up from running through the test plan: RENOVATE_TOKEN does not currently exist in the repo's Actions secrets (only ANTHROPIC_API_KEY, GOOGLE_API_KEY, HOODI_FUNDER_PRIVATE_KEY). The workflow as written will fail on first run.

Two options:

  1. Add the secret before merging. Renovate's Action wants a PAT with repo + workflow scopes, or a fine-grained PAT scoped to this repo with Contents: write, Pull requests: write, Actions: read. Generate one under a dedicated service identity and add it as RENOVATE_TOKEN.
  2. Drop the secret reference and use GITHUB_TOKEN. Works fine for opening PRs in the same repo; the only catch is PRs opened by GITHUB_TOKEN don't trigger other workflows on the resulting PRs (so CI wouldn't auto-run on Renovate PRs unless you swap in a PAT for that purpose).

Happy to push option 2 onto this branch if you'd prefer to avoid the secret management overhead.

@OisinKyne

Copy link
Copy Markdown
Contributor

push option 2?

OisinKyneand others added 2 commits May 11, 2026 13:24
Per review feedback. The repo doesn't currently have a RENOVATE_TOKEN
secret configured; switching to the workflow-scoped GITHUB_TOKEN avoids
the need to mint and rotate a personal access token.
Adds an explicit permissions block so the workflow can:
- write contents: create the renovate/* branches it commits updates to
- write pull-requests: open the PRs themselves
- write issues: maintain Renovate's onboarding/dependency-dashboard issue
Trade-off vs a PAT: PRs opened by GITHUB_TOKEN do not trigger downstream
workflows (so CI checks won't auto-run on Renovate's PRs). If we later
want CI on Renovate PRs we can swap back to a fine-grained PAT.
@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Pushed option 2 in f6852ec: swapped to secrets.GITHUB_TOKEN and added an explicit permissions block (contents: write for the renovate/* branches, pull-requests: write for opening PRs, issues: write for the Dependency Dashboard / onboarding issue).

Trade-off worth flagging: GitHub does not run downstream workflows on PRs opened by GITHUB_TOKEN. So Renovate's PRs won't auto-trigger lint-test etc. until someone closes/reopens them or pushes a commit. If that becomes annoying we can revisit with a fine-grained PAT later.

Comment thread.github/workflows/renovate.yml Outdated
Signed-off-by: Oisín Kyne <4981644+OisinKyne@users.noreply.github.com>
@OisinKyne
OisinKyne merged commit b13254e into mainMay 11, 2026
6 checks passed
@OisinKyne
OisinKyne deleted the chore/add-renovate-workflow branch May 11, 2026 12:33
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@bussyjd@OisinKyne@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci(renovate): add scheduled Renovate workflow - #460

Merged
OisinKyne merged 4 commits into
mainfrom
chore/add-renovate-workflow
May 11, 2026
Merged

ci(renovate): add scheduled Renovate workflow#460
OisinKyne merged 4 commits into
mainfrom
chore/add-renovate-workflow

Conversation

@bussyjd

@bussyjdbussyjd commented May 11, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adds .github/workflows/renovate.yml — hourly scheduled Renovate run plus a workflow_dispatch trigger with a dry_run input
  • This workflow was originally introduced in the integration branch behind Review of my sell agent work so far #455 but dropped during the squash merge to main. The existing renovate.json config currently has no runner without it

Test plan

  • Confirmed via gh api repos/.../actions/secrets: RENOVATE_TOKEN is NOT yet configured. Repo has only ANTHROPIC_API_KEY, GOOGLE_API_KEY, HOODI_FUNDER_PRIVATE_KEY. See comment thread — needs either a PAT secret added before merge, or a swap to GITHUB_TOKEN + pull-requests: write permission
  • Once secret resolved + merged, trigger via Actions → Renovate → Run workflow with dry_run=true and verify the run completes without opening PRs
  • Confirm the next hourly schedule fires and Renovate processes the existing renovate.json managers (frontend tag, gateway API version, image pins)

Adds an hourly scheduled Renovate workflow plus manual workflow_dispatch
trigger. This workflow was introduced in the integration branch behind
PR #455 but dropped during the squash merge to main; the existing
renovate.json config has no runner without it.
Requires the RENOVATE_TOKEN secret to be configured on the repository.
Comment thread.github/workflows/renovate.yml Fixed
@OisinKyne

OisinKyne commented May 11, 2026

Copy link
Copy Markdown
Contributor

please confirm whether dropping the workflow file from #455 was intentional (e.g. you're relying on the hosted Mend Renovate GitHub App).

No, deleting renovate maybe wasn't intentional? i see no deletions in that pr? it adds a renovate file? but maybe we're supposed to use github built in renovate not a third party renovate bot, idk. I just wanted pr bumps for more version checking.

https://github.com/ObolNetwork/obol-stack/pull/455/changes#diff-2f2dcee4f3f279ea8d2f4cd0235f2ab917d8cf1d8e11f4f195a3816afe79af26R1

@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Quick clarification on the timeline so this isn't ambiguous:

So this PR re-adds what got lost during the squash, nothing more. Independent of the hosted-vs-self-hosted question — renovate.json config currently has nothing to actually run it because no Renovate Action lives in .github/workflows/. If we later prefer the Mend GitHub App route, we can swap by uninstalling this workflow and installing the App; the config file stays the same.

If you're happy, I'll merge once #460 has a tick.

@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Heads-up from running through the test plan: RENOVATE_TOKEN does not currently exist in the repo's Actions secrets (only ANTHROPIC_API_KEY, GOOGLE_API_KEY, HOODI_FUNDER_PRIVATE_KEY). The workflow as written will fail on first run.

Two options:

  1. Add the secret before merging. Renovate's Action wants a PAT with repo + workflow scopes, or a fine-grained PAT scoped to this repo with Contents: write, Pull requests: write, Actions: read. Generate one under a dedicated service identity and add it as RENOVATE_TOKEN.
  2. Drop the secret reference and use GITHUB_TOKEN. Works fine for opening PRs in the same repo; the only catch is PRs opened by GITHUB_TOKEN don't trigger other workflows on the resulting PRs (so CI wouldn't auto-run on Renovate PRs unless you swap in a PAT for that purpose).

Happy to push option 2 onto this branch if you'd prefer to avoid the secret management overhead.

@OisinKyne

Copy link
Copy Markdown
Contributor

push option 2?

OisinKyneand others added 2 commits May 11, 2026 13:24
Per review feedback. The repo doesn't currently have a RENOVATE_TOKEN
secret configured; switching to the workflow-scoped GITHUB_TOKEN avoids
the need to mint and rotate a personal access token.
Adds an explicit permissions block so the workflow can:
- write contents: create the renovate/* branches it commits updates to
- write pull-requests: open the PRs themselves
- write issues: maintain Renovate's onboarding/dependency-dashboard issue
Trade-off vs a PAT: PRs opened by GITHUB_TOKEN do not trigger downstream
workflows (so CI checks won't auto-run on Renovate's PRs). If we later
want CI on Renovate PRs we can swap back to a fine-grained PAT.
@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Pushed option 2 in f6852ec: swapped to secrets.GITHUB_TOKEN and added an explicit permissions block (contents: write for the renovate/* branches, pull-requests: write for opening PRs, issues: write for the Dependency Dashboard / onboarding issue).

Trade-off worth flagging: GitHub does not run downstream workflows on PRs opened by GITHUB_TOKEN. So Renovate's PRs won't auto-trigger lint-test etc. until someone closes/reopens them or pushes a commit. If that becomes annoying we can revisit with a fine-grained PAT later.

Comment thread.github/workflows/renovate.yml Outdated
Signed-off-by: Oisín Kyne <4981644+OisinKyne@users.noreply.github.com>
@OisinKyne
OisinKyne merged commit b13254e into mainMay 11, 2026
6 checks passed
@OisinKyne
OisinKyne deleted the chore/add-renovate-workflow branch May 11, 2026 12:33
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@bussyjd@OisinKyne@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

ci(renovate): add scheduled Renovate workflow - #460

Merged
OisinKyne merged 4 commits into
mainfrom
chore/add-renovate-workflow
May 11, 2026
Merged

ci(renovate): add scheduled Renovate workflow#460
OisinKyne merged 4 commits into
mainfrom
chore/add-renovate-workflow

Conversation

@bussyjd

@bussyjdbussyjd commented May 11, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adds .github/workflows/renovate.yml — hourly scheduled Renovate run plus a workflow_dispatch trigger with a dry_run input
  • This workflow was originally introduced in the integration branch behind Review of my sell agent work so far #455 but dropped during the squash merge to main. The existing renovate.json config currently has no runner without it

Test plan

  • Confirmed via gh api repos/.../actions/secrets: RENOVATE_TOKEN is NOT yet configured. Repo has only ANTHROPIC_API_KEY, GOOGLE_API_KEY, HOODI_FUNDER_PRIVATE_KEY. See comment thread — needs either a PAT secret added before merge, or a swap to GITHUB_TOKEN + pull-requests: write permission
  • Once secret resolved + merged, trigger via Actions → Renovate → Run workflow with dry_run=true and verify the run completes without opening PRs
  • Confirm the next hourly schedule fires and Renovate processes the existing renovate.json managers (frontend tag, gateway API version, image pins)

Adds an hourly scheduled Renovate workflow plus manual workflow_dispatch
trigger. This workflow was introduced in the integration branch behind
PR #455 but dropped during the squash merge to main; the existing
renovate.json config has no runner without it.
Requires the RENOVATE_TOKEN secret to be configured on the repository.
Comment thread.github/workflows/renovate.yml Fixed
@OisinKyne

OisinKyne commented May 11, 2026

Copy link
Copy Markdown
Contributor

please confirm whether dropping the workflow file from #455 was intentional (e.g. you're relying on the hosted Mend Renovate GitHub App).

No, deleting renovate maybe wasn't intentional? i see no deletions in that pr? it adds a renovate file? but maybe we're supposed to use github built in renovate not a third party renovate bot, idk. I just wanted pr bumps for more version checking.

https://github.com/ObolNetwork/obol-stack/pull/455/changes#diff-2f2dcee4f3f279ea8d2f4cd0235f2ab917d8cf1d8e11f4f195a3816afe79af26R1

@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Quick clarification on the timeline so this isn't ambiguous:

So this PR re-adds what got lost during the squash, nothing more. Independent of the hosted-vs-self-hosted question — renovate.json config currently has nothing to actually run it because no Renovate Action lives in .github/workflows/. If we later prefer the Mend GitHub App route, we can swap by uninstalling this workflow and installing the App; the config file stays the same.

If you're happy, I'll merge once #460 has a tick.

@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Heads-up from running through the test plan: RENOVATE_TOKEN does not currently exist in the repo's Actions secrets (only ANTHROPIC_API_KEY, GOOGLE_API_KEY, HOODI_FUNDER_PRIVATE_KEY). The workflow as written will fail on first run.

Two options:

  1. Add the secret before merging. Renovate's Action wants a PAT with repo + workflow scopes, or a fine-grained PAT scoped to this repo with Contents: write, Pull requests: write, Actions: read. Generate one under a dedicated service identity and add it as RENOVATE_TOKEN.
  2. Drop the secret reference and use GITHUB_TOKEN. Works fine for opening PRs in the same repo; the only catch is PRs opened by GITHUB_TOKEN don't trigger other workflows on the resulting PRs (so CI wouldn't auto-run on Renovate PRs unless you swap in a PAT for that purpose).

Happy to push option 2 onto this branch if you'd prefer to avoid the secret management overhead.

@OisinKyne

Copy link
Copy Markdown
Contributor

push option 2?

OisinKyneand others added 2 commits May 11, 2026 13:24
Per review feedback. The repo doesn't currently have a RENOVATE_TOKEN
secret configured; switching to the workflow-scoped GITHUB_TOKEN avoids
the need to mint and rotate a personal access token.
Adds an explicit permissions block so the workflow can:
- write contents: create the renovate/* branches it commits updates to
- write pull-requests: open the PRs themselves
- write issues: maintain Renovate's onboarding/dependency-dashboard issue
Trade-off vs a PAT: PRs opened by GITHUB_TOKEN do not trigger downstream
workflows (so CI checks won't auto-run on Renovate's PRs). If we later
want CI on Renovate PRs we can swap back to a fine-grained PAT.
@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Pushed option 2 in f6852ec: swapped to secrets.GITHUB_TOKEN and added an explicit permissions block (contents: write for the renovate/* branches, pull-requests: write for opening PRs, issues: write for the Dependency Dashboard / onboarding issue).

Trade-off worth flagging: GitHub does not run downstream workflows on PRs opened by GITHUB_TOKEN. So Renovate's PRs won't auto-trigger lint-test etc. until someone closes/reopens them or pushes a commit. If that becomes annoying we can revisit with a fine-grained PAT later.

Comment thread.github/workflows/renovate.yml Outdated
Signed-off-by: Oisín Kyne <4981644+OisinKyne@users.noreply.github.com>
@OisinKyne
OisinKyne merged commit b13254e into mainMay 11, 2026
6 checks passed
@OisinKyne
OisinKyne deleted the chore/add-renovate-workflow branch May 11, 2026 12:33
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@bussyjd@OisinKyne@github-advanced-security