[build] remove overly complicated renovate workflow - #17525

Merged
titusfortner merged 2 commits into
trunkfrom
dependency_workflows
May 19, 2026
Merged

[build] remove overly complicated renovate workflow#17525
titusfortner merged 2 commits into
trunkfrom
dependency_workflows

Conversation

@titusfortner

Copy link
Copy Markdown
Member

🔗 Related Issues

#17504 was not a good approach (shocking I made it too complicated)
Turns out we can adjust renovate not to actually create PRs but just to create branches we can run tests against

💥 What does this PR do?

This is just to prove out the approach:

  • Renovate should create a single branch here
  • ci-renovate-rbe should kick off and run tests

🔧 Implementation Notes

This is the better alternative

🤖 AI assistance

  • No substantial AI assistance used
  • AI assisted (complete below)
    • Tool(s): claude
    • What was generated: json settings
    • I reviewed all AI output and can explain the change

💡 Additional Considerations

Follow on is to:

  • Decide on Auto merge (maybe break into major/minor)
  • expand to more than one branch at a time
  • manage failures

@selenium-ciselenium-ci added the B-build Includes scripting, bazel and CI integrations label May 19, 2026
@qodo-code-review

Copy link
Copy Markdown
Contributor

Review Summary by Qodo

Simplify dependency workflow with Renovate branch-based testing

✨ Enhancement

Grey Divider

Walkthroughs

Description
• Simplify dependency update workflow using Renovate's built-in branch creation
• Remove complex multi-step orchestration in favor of automatic branch-based testing
• Add new ci-renovate-rbe.yml workflow to test and commit dependency updates
• Update Renovate configuration to create branches instead of pull requests
Diagram
flowchart LR
A["Renovate creates<br/>renovate/* branches"] --> B["ci-renovate-rbe<br/>workflow triggers"]
B --> C["Repin dependencies<br/>and format"]
C --> D["Commit changes<br/>to branch"]
D --> E["Run RBE tests"]
E --> F["Run GitHub CI"]
Loading

Grey Divider

File Changes

1. .github/workflows/ci-rbe.yml ✨ Enhancement +2/-1

Add workflow_call trigger and remove renovate exclusion

• Add workflow_call trigger to allow reuse from other workflows
• Remove condition that excluded renovate branches from running tests
• Simplify job condition to only check for fork status

.github/workflows/ci-rbe.yml


2. .github/workflows/ci-renovate-rbe.yml ✨ Enhancement +43/-0

New workflow for testing renovate dependency branches

• New workflow triggered on renovate/* branch pushes
• Repin dependencies using ./go all:pin and ./go rust:pin
• Commit repins to branch and run full test suite
• Chain RBE tests and GitHub CI tests after successful commits

.github/workflows/ci-renovate-rbe.yml


3. .github/workflows/renovate-dependencies.yml ✨ Enhancement +0/-102

Remove overly complicated renovate orchestration workflow

• Completely removed complex orchestration workflow
• Eliminated manual branch reset and Renovate invocation logic
• Removed matrix-based major/minor dependency PR creation

.github/workflows/renovate-dependencies.yml


View more (2)
4. .github/workflows/renovate-dependency-pr.yml ✨ Enhancement +0/-106

Remove complex dependency PR creation workflow

• Completely removed workflow that created individual dependency PRs
• Eliminated branch detection and patch-based promotion logic
• Removed dependency on manual workflow orchestration

.github/workflows/renovate-dependency-pr.yml


5. renovate.json ⚙️ Configuration changes +3/-21

Configure Renovate for branch-based testing approach

• Set prCreation: "approval" to prevent automatic PR creation
• Add branchConcurrentLimit: 1 to limit concurrent dependency branches
• Remove dependencyDashboardApproval and automerge settings
• Update dashboard header to explain new branch-based workflow
• Remove orchestration-specific grouping rules for major/minor updates

renovate.json


Grey Divider

Qodo Logo

@qodo-code-review

qodo-code-reviewBot commented May 19, 2026

Copy link
Copy Markdown
Contributor

Code Review by Qodo

🐞 Bugs (1)📘 Rule violations (0)

Grey Divider


Remediation recommended

1. Force-push branch race 🐞 Bug☼ Reliability
Description
ci-renovate-rbe.yml triggers on push to renovate/* and then calls commit-changes.yml, which
force-pushes back to that same branch; without per-branch workflow concurrency this can overwrite
newer Renovate commits (or run CI on commits that are no longer the branch head). This is especially
risky if Renovate pushes additional commits to the branch while the workflow is still running.
Code

.github/workflows/ci-renovate-rbe.yml[R3-34]

+on:+ push:+ branches:+ - renovate/*++permissions:+ contents: read++jobs:+ pin:+ name: Repin Dependencies+ if: github.event.repository.fork == false+ uses: ./.github/workflows/bazel.yml+ with:+ name: Repin Dependencies+ run: |+ ./go all:pin+ ./go rust:pin+ ./go format+ artifact-name: repin-changes++ commit-repins:+ name: Commit Repins+ needs: pin+ permissions:+ contents: write+ actions: read+ uses: ./.github/workflows/commit-changes.yml+ with:+ artifact-name: repin-changes+ commit-message: "Repin dependencies"+
Evidence
The new workflow triggers on pushes to renovate/* and invokes the reusable commit workflow. That
reusable workflow force-pushes (git push --force) to the target branch, which can clobber newer
remote commits if another push lands while the run is executing; adding per-branch
concurrency/cancellation (and/or --force-with-lease) prevents these races.

.github/workflows/ci-renovate-rbe.yml[3-43]
.github/workflows/commit-changes.yml[46-59]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution
### Issue description
The new `CI - Renovate - RBE` workflow runs on every push to `renovate/*` and then executes a force-push back to the same branch (via `commit-changes.yml`). Without a per-branch concurrency group, overlapping runs for the same branch (e.g., Renovate pushes again while CI is running) can lead to:
- wasted CI on superseded heads
- or worse: the force-push overwriting newer Renovate commits
### Issue Context
- The workflow is `on: push` for `renovate/*`.
- It uses `commit-changes.yml`, which does `git push --force`.
### Fix Focus Areas
- Add workflow-level concurrency scoped to the branch ref to serialize/cancel runs:
- `.github/workflows/ci-renovate-rbe.yml[1-43]`
- Consider making the push safer by switching to `--force-with-lease` to avoid overwriting remote updates:
- `.github/workflows/commit-changes.yml[46-56]`

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Qodo Logo

@titusfortner
titusfortner merged commit 72a6efd into trunkMay 19, 2026
17 checks passed
@titusfortner
titusfortner deleted the dependency_workflows branch May 19, 2026 17:14
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

B-buildIncludes scripting, bazel and CI integrations

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@titusfortner@selenium-ci
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

[build] remove overly complicated renovate workflow - #17525

Merged
titusfortner merged 2 commits into
trunkfrom
dependency_workflows
May 19, 2026
Merged

[build] remove overly complicated renovate workflow#17525
titusfortner merged 2 commits into
trunkfrom
dependency_workflows

Conversation

@titusfortner

Copy link
Copy Markdown
Member

🔗 Related Issues

#17504 was not a good approach (shocking I made it too complicated)
Turns out we can adjust renovate not to actually create PRs but just to create branches we can run tests against

💥 What does this PR do?

This is just to prove out the approach:

  • Renovate should create a single branch here
  • ci-renovate-rbe should kick off and run tests

🔧 Implementation Notes

This is the better alternative

🤖 AI assistance

  • No substantial AI assistance used
  • AI assisted (complete below)
    • Tool(s): claude
    • What was generated: json settings
    • I reviewed all AI output and can explain the change

💡 Additional Considerations

Follow on is to:

  • Decide on Auto merge (maybe break into major/minor)
  • expand to more than one branch at a time
  • manage failures

@selenium-ciselenium-ci added the B-build Includes scripting, bazel and CI integrations label May 19, 2026
@qodo-code-review

Copy link
Copy Markdown
Contributor

Review Summary by Qodo

Simplify dependency workflow with Renovate branch-based testing

✨ Enhancement

Grey Divider

Walkthroughs

Description
• Simplify dependency update workflow using Renovate's built-in branch creation
• Remove complex multi-step orchestration in favor of automatic branch-based testing
• Add new ci-renovate-rbe.yml workflow to test and commit dependency updates
• Update Renovate configuration to create branches instead of pull requests
Diagram
flowchart LR
A["Renovate creates<br/>renovate/* branches"] --> B["ci-renovate-rbe<br/>workflow triggers"]
B --> C["Repin dependencies<br/>and format"]
C --> D["Commit changes<br/>to branch"]
D --> E["Run RBE tests"]
E --> F["Run GitHub CI"]
Loading

Grey Divider

File Changes

1. .github/workflows/ci-rbe.yml ✨ Enhancement +2/-1

Add workflow_call trigger and remove renovate exclusion

• Add workflow_call trigger to allow reuse from other workflows
• Remove condition that excluded renovate branches from running tests
• Simplify job condition to only check for fork status

.github/workflows/ci-rbe.yml


2. .github/workflows/ci-renovate-rbe.yml ✨ Enhancement +43/-0

New workflow for testing renovate dependency branches

• New workflow triggered on renovate/* branch pushes
• Repin dependencies using ./go all:pin and ./go rust:pin
• Commit repins to branch and run full test suite
• Chain RBE tests and GitHub CI tests after successful commits

.github/workflows/ci-renovate-rbe.yml


3. .github/workflows/renovate-dependencies.yml ✨ Enhancement +0/-102

Remove overly complicated renovate orchestration workflow

• Completely removed complex orchestration workflow
• Eliminated manual branch reset and Renovate invocation logic
• Removed matrix-based major/minor dependency PR creation

.github/workflows/renovate-dependencies.yml


View more (2)
4. .github/workflows/renovate-dependency-pr.yml ✨ Enhancement +0/-106

Remove complex dependency PR creation workflow

• Completely removed workflow that created individual dependency PRs
• Eliminated branch detection and patch-based promotion logic
• Removed dependency on manual workflow orchestration

.github/workflows/renovate-dependency-pr.yml


5. renovate.json ⚙️ Configuration changes +3/-21

Configure Renovate for branch-based testing approach

• Set prCreation: "approval" to prevent automatic PR creation
• Add branchConcurrentLimit: 1 to limit concurrent dependency branches
• Remove dependencyDashboardApproval and automerge settings
• Update dashboard header to explain new branch-based workflow
• Remove orchestration-specific grouping rules for major/minor updates

renovate.json


Grey Divider

Qodo Logo

@qodo-code-review

qodo-code-reviewBot commented May 19, 2026

Copy link
Copy Markdown
Contributor

Code Review by Qodo

🐞 Bugs (1)📘 Rule violations (0)

Grey Divider


Remediation recommended

1. Force-push branch race 🐞 Bug☼ Reliability
Description
ci-renovate-rbe.yml triggers on push to renovate/* and then calls commit-changes.yml, which
force-pushes back to that same branch; without per-branch workflow concurrency this can overwrite
newer Renovate commits (or run CI on commits that are no longer the branch head). This is especially
risky if Renovate pushes additional commits to the branch while the workflow is still running.
Code

.github/workflows/ci-renovate-rbe.yml[R3-34]

+on:+ push:+ branches:+ - renovate/*++permissions:+ contents: read++jobs:+ pin:+ name: Repin Dependencies+ if: github.event.repository.fork == false+ uses: ./.github/workflows/bazel.yml+ with:+ name: Repin Dependencies+ run: |+ ./go all:pin+ ./go rust:pin+ ./go format+ artifact-name: repin-changes++ commit-repins:+ name: Commit Repins+ needs: pin+ permissions:+ contents: write+ actions: read+ uses: ./.github/workflows/commit-changes.yml+ with:+ artifact-name: repin-changes+ commit-message: "Repin dependencies"+
Evidence
The new workflow triggers on pushes to renovate/* and invokes the reusable commit workflow. That
reusable workflow force-pushes (git push --force) to the target branch, which can clobber newer
remote commits if another push lands while the run is executing; adding per-branch
concurrency/cancellation (and/or --force-with-lease) prevents these races.

.github/workflows/ci-renovate-rbe.yml[3-43]
.github/workflows/commit-changes.yml[46-59]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution
### Issue description
The new `CI - Renovate - RBE` workflow runs on every push to `renovate/*` and then executes a force-push back to the same branch (via `commit-changes.yml`). Without a per-branch concurrency group, overlapping runs for the same branch (e.g., Renovate pushes again while CI is running) can lead to:
- wasted CI on superseded heads
- or worse: the force-push overwriting newer Renovate commits
### Issue Context
- The workflow is `on: push` for `renovate/*`.
- It uses `commit-changes.yml`, which does `git push --force`.
### Fix Focus Areas
- Add workflow-level concurrency scoped to the branch ref to serialize/cancel runs:
- `.github/workflows/ci-renovate-rbe.yml[1-43]`
- Consider making the push safer by switching to `--force-with-lease` to avoid overwriting remote updates:
- `.github/workflows/commit-changes.yml[46-56]`

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Qodo Logo

@titusfortner
titusfortner merged commit 72a6efd into trunkMay 19, 2026
17 checks passed
@titusfortner
titusfortner deleted the dependency_workflows branch May 19, 2026 17:14
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

B-buildIncludes scripting, bazel and CI integrations

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@titusfortner@selenium-ci
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[build] remove overly complicated renovate workflow - #17525

Merged
titusfortner merged 2 commits into
trunkfrom
dependency_workflows
May 19, 2026
Merged

[build] remove overly complicated renovate workflow#17525
titusfortner merged 2 commits into
trunkfrom
dependency_workflows

Conversation

@titusfortner

Copy link
Copy Markdown
Member

🔗 Related Issues

#17504 was not a good approach (shocking I made it too complicated)
Turns out we can adjust renovate not to actually create PRs but just to create branches we can run tests against

💥 What does this PR do?

This is just to prove out the approach:

  • Renovate should create a single branch here
  • ci-renovate-rbe should kick off and run tests

🔧 Implementation Notes

This is the better alternative

🤖 AI assistance

  • No substantial AI assistance used
  • AI assisted (complete below)
    • Tool(s): claude
    • What was generated: json settings
    • I reviewed all AI output and can explain the change

💡 Additional Considerations

Follow on is to:

  • Decide on Auto merge (maybe break into major/minor)
  • expand to more than one branch at a time
  • manage failures

@selenium-ciselenium-ci added the B-build Includes scripting, bazel and CI integrations label May 19, 2026
@qodo-code-review

Copy link
Copy Markdown
Contributor

Review Summary by Qodo

Simplify dependency workflow with Renovate branch-based testing

✨ Enhancement

Grey Divider

Walkthroughs

Description
• Simplify dependency update workflow using Renovate's built-in branch creation
• Remove complex multi-step orchestration in favor of automatic branch-based testing
• Add new ci-renovate-rbe.yml workflow to test and commit dependency updates
• Update Renovate configuration to create branches instead of pull requests
Diagram
flowchart LR
A["Renovate creates<br/>renovate/* branches"] --> B["ci-renovate-rbe<br/>workflow triggers"]
B --> C["Repin dependencies<br/>and format"]
C --> D["Commit changes<br/>to branch"]
D --> E["Run RBE tests"]
E --> F["Run GitHub CI"]
Loading

Grey Divider

File Changes

1. .github/workflows/ci-rbe.yml ✨ Enhancement +2/-1

Add workflow_call trigger and remove renovate exclusion

• Add workflow_call trigger to allow reuse from other workflows
• Remove condition that excluded renovate branches from running tests
• Simplify job condition to only check for fork status

.github/workflows/ci-rbe.yml


2. .github/workflows/ci-renovate-rbe.yml ✨ Enhancement +43/-0

New workflow for testing renovate dependency branches

• New workflow triggered on renovate/* branch pushes
• Repin dependencies using ./go all:pin and ./go rust:pin
• Commit repins to branch and run full test suite
• Chain RBE tests and GitHub CI tests after successful commits

.github/workflows/ci-renovate-rbe.yml


3. .github/workflows/renovate-dependencies.yml ✨ Enhancement +0/-102

Remove overly complicated renovate orchestration workflow

• Completely removed complex orchestration workflow
• Eliminated manual branch reset and Renovate invocation logic
• Removed matrix-based major/minor dependency PR creation

.github/workflows/renovate-dependencies.yml


View more (2)
4. .github/workflows/renovate-dependency-pr.yml ✨ Enhancement +0/-106

Remove complex dependency PR creation workflow

• Completely removed workflow that created individual dependency PRs
• Eliminated branch detection and patch-based promotion logic
• Removed dependency on manual workflow orchestration

.github/workflows/renovate-dependency-pr.yml


5. renovate.json ⚙️ Configuration changes +3/-21

Configure Renovate for branch-based testing approach

• Set prCreation: "approval" to prevent automatic PR creation
• Add branchConcurrentLimit: 1 to limit concurrent dependency branches
• Remove dependencyDashboardApproval and automerge settings
• Update dashboard header to explain new branch-based workflow
• Remove orchestration-specific grouping rules for major/minor updates

renovate.json


Grey Divider

Qodo Logo

@qodo-code-review

qodo-code-reviewBot commented May 19, 2026

Copy link
Copy Markdown
Contributor

Code Review by Qodo

🐞 Bugs (1)📘 Rule violations (0)

Grey Divider


Remediation recommended

1. Force-push branch race 🐞 Bug☼ Reliability
Description
ci-renovate-rbe.yml triggers on push to renovate/* and then calls commit-changes.yml, which
force-pushes back to that same branch; without per-branch workflow concurrency this can overwrite
newer Renovate commits (or run CI on commits that are no longer the branch head). This is especially
risky if Renovate pushes additional commits to the branch while the workflow is still running.
Code

.github/workflows/ci-renovate-rbe.yml[R3-34]

+on:+ push:+ branches:+ - renovate/*++permissions:+ contents: read++jobs:+ pin:+ name: Repin Dependencies+ if: github.event.repository.fork == false+ uses: ./.github/workflows/bazel.yml+ with:+ name: Repin Dependencies+ run: |+ ./go all:pin+ ./go rust:pin+ ./go format+ artifact-name: repin-changes++ commit-repins:+ name: Commit Repins+ needs: pin+ permissions:+ contents: write+ actions: read+ uses: ./.github/workflows/commit-changes.yml+ with:+ artifact-name: repin-changes+ commit-message: "Repin dependencies"+
Evidence
The new workflow triggers on pushes to renovate/* and invokes the reusable commit workflow. That
reusable workflow force-pushes (git push --force) to the target branch, which can clobber newer
remote commits if another push lands while the run is executing; adding per-branch
concurrency/cancellation (and/or --force-with-lease) prevents these races.

.github/workflows/ci-renovate-rbe.yml[3-43]
.github/workflows/commit-changes.yml[46-59]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution
### Issue description
The new `CI - Renovate - RBE` workflow runs on every push to `renovate/*` and then executes a force-push back to the same branch (via `commit-changes.yml`). Without a per-branch concurrency group, overlapping runs for the same branch (e.g., Renovate pushes again while CI is running) can lead to:
- wasted CI on superseded heads
- or worse: the force-push overwriting newer Renovate commits
### Issue Context
- The workflow is `on: push` for `renovate/*`.
- It uses `commit-changes.yml`, which does `git push --force`.
### Fix Focus Areas
- Add workflow-level concurrency scoped to the branch ref to serialize/cancel runs:
- `.github/workflows/ci-renovate-rbe.yml[1-43]`
- Consider making the push safer by switching to `--force-with-lease` to avoid overwriting remote updates:
- `.github/workflows/commit-changes.yml[46-56]`

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Qodo Logo

@titusfortner
titusfortner merged commit 72a6efd into trunkMay 19, 2026
17 checks passed
@titusfortner
titusfortner deleted the dependency_workflows branch May 19, 2026 17:14
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

B-buildIncludes scripting, bazel and CI integrations

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@titusfortner@selenium-ci
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[build] remove overly complicated renovate workflow - #17525

Merged
titusfortner merged 2 commits into
trunkfrom
dependency_workflows
May 19, 2026
Merged

[build] remove overly complicated renovate workflow#17525
titusfortner merged 2 commits into
trunkfrom
dependency_workflows

Conversation

@titusfortner

Copy link
Copy Markdown
Member

🔗 Related Issues

#17504 was not a good approach (shocking I made it too complicated)
Turns out we can adjust renovate not to actually create PRs but just to create branches we can run tests against

💥 What does this PR do?

This is just to prove out the approach:

  • Renovate should create a single branch here
  • ci-renovate-rbe should kick off and run tests

🔧 Implementation Notes

This is the better alternative

🤖 AI assistance

  • No substantial AI assistance used
  • AI assisted (complete below)
    • Tool(s): claude
    • What was generated: json settings
    • I reviewed all AI output and can explain the change

💡 Additional Considerations

Follow on is to:

  • Decide on Auto merge (maybe break into major/minor)
  • expand to more than one branch at a time
  • manage failures

@selenium-ciselenium-ci added the B-build Includes scripting, bazel and CI integrations label May 19, 2026
@qodo-code-review

Copy link
Copy Markdown
Contributor

Review Summary by Qodo

Simplify dependency workflow with Renovate branch-based testing

✨ Enhancement

Grey Divider

Walkthroughs

Description
• Simplify dependency update workflow using Renovate's built-in branch creation
• Remove complex multi-step orchestration in favor of automatic branch-based testing
• Add new ci-renovate-rbe.yml workflow to test and commit dependency updates
• Update Renovate configuration to create branches instead of pull requests
Diagram
flowchart LR
A["Renovate creates<br/>renovate/* branches"] --> B["ci-renovate-rbe<br/>workflow triggers"]
B --> C["Repin dependencies<br/>and format"]
C --> D["Commit changes<br/>to branch"]
D --> E["Run RBE tests"]
E --> F["Run GitHub CI"]
Loading

Grey Divider

File Changes

1. .github/workflows/ci-rbe.yml ✨ Enhancement +2/-1

Add workflow_call trigger and remove renovate exclusion

• Add workflow_call trigger to allow reuse from other workflows
• Remove condition that excluded renovate branches from running tests
• Simplify job condition to only check for fork status

.github/workflows/ci-rbe.yml


2. .github/workflows/ci-renovate-rbe.yml ✨ Enhancement +43/-0

New workflow for testing renovate dependency branches

• New workflow triggered on renovate/* branch pushes
• Repin dependencies using ./go all:pin and ./go rust:pin
• Commit repins to branch and run full test suite
• Chain RBE tests and GitHub CI tests after successful commits

.github/workflows/ci-renovate-rbe.yml


3. .github/workflows/renovate-dependencies.yml ✨ Enhancement +0/-102

Remove overly complicated renovate orchestration workflow

• Completely removed complex orchestration workflow
• Eliminated manual branch reset and Renovate invocation logic
• Removed matrix-based major/minor dependency PR creation

.github/workflows/renovate-dependencies.yml


View more (2)
4. .github/workflows/renovate-dependency-pr.yml ✨ Enhancement +0/-106

Remove complex dependency PR creation workflow

• Completely removed workflow that created individual dependency PRs
• Eliminated branch detection and patch-based promotion logic
• Removed dependency on manual workflow orchestration

.github/workflows/renovate-dependency-pr.yml


5. renovate.json ⚙️ Configuration changes +3/-21

Configure Renovate for branch-based testing approach

• Set prCreation: "approval" to prevent automatic PR creation
• Add branchConcurrentLimit: 1 to limit concurrent dependency branches
• Remove dependencyDashboardApproval and automerge settings
• Update dashboard header to explain new branch-based workflow
• Remove orchestration-specific grouping rules for major/minor updates

renovate.json


Grey Divider

Qodo Logo

@qodo-code-review

qodo-code-reviewBot commented May 19, 2026

Copy link
Copy Markdown
Contributor

Code Review by Qodo

🐞 Bugs (1)📘 Rule violations (0)

Grey Divider


Remediation recommended

1. Force-push branch race 🐞 Bug☼ Reliability
Description
ci-renovate-rbe.yml triggers on push to renovate/* and then calls commit-changes.yml, which
force-pushes back to that same branch; without per-branch workflow concurrency this can overwrite
newer Renovate commits (or run CI on commits that are no longer the branch head). This is especially
risky if Renovate pushes additional commits to the branch while the workflow is still running.
Code

.github/workflows/ci-renovate-rbe.yml[R3-34]

+on:+ push:+ branches:+ - renovate/*++permissions:+ contents: read++jobs:+ pin:+ name: Repin Dependencies+ if: github.event.repository.fork == false+ uses: ./.github/workflows/bazel.yml+ with:+ name: Repin Dependencies+ run: |+ ./go all:pin+ ./go rust:pin+ ./go format+ artifact-name: repin-changes++ commit-repins:+ name: Commit Repins+ needs: pin+ permissions:+ contents: write+ actions: read+ uses: ./.github/workflows/commit-changes.yml+ with:+ artifact-name: repin-changes+ commit-message: "Repin dependencies"+
Evidence
The new workflow triggers on pushes to renovate/* and invokes the reusable commit workflow. That
reusable workflow force-pushes (git push --force) to the target branch, which can clobber newer
remote commits if another push lands while the run is executing; adding per-branch
concurrency/cancellation (and/or --force-with-lease) prevents these races.

.github/workflows/ci-renovate-rbe.yml[3-43]
.github/workflows/commit-changes.yml[46-59]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution
### Issue description
The new `CI - Renovate - RBE` workflow runs on every push to `renovate/*` and then executes a force-push back to the same branch (via `commit-changes.yml`). Without a per-branch concurrency group, overlapping runs for the same branch (e.g., Renovate pushes again while CI is running) can lead to:
- wasted CI on superseded heads
- or worse: the force-push overwriting newer Renovate commits
### Issue Context
- The workflow is `on: push` for `renovate/*`.
- It uses `commit-changes.yml`, which does `git push --force`.
### Fix Focus Areas
- Add workflow-level concurrency scoped to the branch ref to serialize/cancel runs:
- `.github/workflows/ci-renovate-rbe.yml[1-43]`
- Consider making the push safer by switching to `--force-with-lease` to avoid overwriting remote updates:
- `.github/workflows/commit-changes.yml[46-56]`

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Qodo Logo

@titusfortner
titusfortner merged commit 72a6efd into trunkMay 19, 2026
17 checks passed
@titusfortner
titusfortner deleted the dependency_workflows branch May 19, 2026 17:14
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

B-buildIncludes scripting, bazel and CI integrations

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@titusfortner@selenium-ci
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

[build] remove overly complicated renovate workflow - #17525

Merged
titusfortner merged 2 commits into
trunkfrom
dependency_workflows
May 19, 2026
Merged

[build] remove overly complicated renovate workflow#17525
titusfortner merged 2 commits into
trunkfrom
dependency_workflows

Conversation

@titusfortner

Copy link
Copy Markdown
Member

🔗 Related Issues

#17504 was not a good approach (shocking I made it too complicated)
Turns out we can adjust renovate not to actually create PRs but just to create branches we can run tests against

💥 What does this PR do?

This is just to prove out the approach:

  • Renovate should create a single branch here
  • ci-renovate-rbe should kick off and run tests

🔧 Implementation Notes

This is the better alternative

🤖 AI assistance

  • No substantial AI assistance used
  • AI assisted (complete below)
    • Tool(s): claude
    • What was generated: json settings
    • I reviewed all AI output and can explain the change

💡 Additional Considerations

Follow on is to:

  • Decide on Auto merge (maybe break into major/minor)
  • expand to more than one branch at a time
  • manage failures

@selenium-ciselenium-ci added the B-build Includes scripting, bazel and CI integrations label May 19, 2026
@qodo-code-review

Copy link
Copy Markdown
Contributor

Review Summary by Qodo

Simplify dependency workflow with Renovate branch-based testing

✨ Enhancement

Grey Divider

Walkthroughs

Description
• Simplify dependency update workflow using Renovate's built-in branch creation
• Remove complex multi-step orchestration in favor of automatic branch-based testing
• Add new ci-renovate-rbe.yml workflow to test and commit dependency updates
• Update Renovate configuration to create branches instead of pull requests
Diagram
flowchart LR
A["Renovate creates<br/>renovate/* branches"] --> B["ci-renovate-rbe<br/>workflow triggers"]
B --> C["Repin dependencies<br/>and format"]
C --> D["Commit changes<br/>to branch"]
D --> E["Run RBE tests"]
E --> F["Run GitHub CI"]
Loading

Grey Divider

File Changes

1. .github/workflows/ci-rbe.yml ✨ Enhancement +2/-1

Add workflow_call trigger and remove renovate exclusion

• Add workflow_call trigger to allow reuse from other workflows
• Remove condition that excluded renovate branches from running tests
• Simplify job condition to only check for fork status

.github/workflows/ci-rbe.yml


2. .github/workflows/ci-renovate-rbe.yml ✨ Enhancement +43/-0

New workflow for testing renovate dependency branches

• New workflow triggered on renovate/* branch pushes
• Repin dependencies using ./go all:pin and ./go rust:pin
• Commit repins to branch and run full test suite
• Chain RBE tests and GitHub CI tests after successful commits

.github/workflows/ci-renovate-rbe.yml


3. .github/workflows/renovate-dependencies.yml ✨ Enhancement +0/-102

Remove overly complicated renovate orchestration workflow

• Completely removed complex orchestration workflow
• Eliminated manual branch reset and Renovate invocation logic
• Removed matrix-based major/minor dependency PR creation

.github/workflows/renovate-dependencies.yml


View more (2)
4. .github/workflows/renovate-dependency-pr.yml ✨ Enhancement +0/-106

Remove complex dependency PR creation workflow

• Completely removed workflow that created individual dependency PRs
• Eliminated branch detection and patch-based promotion logic
• Removed dependency on manual workflow orchestration

.github/workflows/renovate-dependency-pr.yml


5. renovate.json ⚙️ Configuration changes +3/-21

Configure Renovate for branch-based testing approach

• Set prCreation: "approval" to prevent automatic PR creation
• Add branchConcurrentLimit: 1 to limit concurrent dependency branches
• Remove dependencyDashboardApproval and automerge settings
• Update dashboard header to explain new branch-based workflow
• Remove orchestration-specific grouping rules for major/minor updates

renovate.json


Grey Divider

Qodo Logo

@qodo-code-review

qodo-code-reviewBot commented May 19, 2026

Copy link
Copy Markdown
Contributor

Code Review by Qodo

🐞 Bugs (1)📘 Rule violations (0)

Grey Divider


Remediation recommended

1. Force-push branch race 🐞 Bug☼ Reliability
Description
ci-renovate-rbe.yml triggers on push to renovate/* and then calls commit-changes.yml, which
force-pushes back to that same branch; without per-branch workflow concurrency this can overwrite
newer Renovate commits (or run CI on commits that are no longer the branch head). This is especially
risky if Renovate pushes additional commits to the branch while the workflow is still running.
Code

.github/workflows/ci-renovate-rbe.yml[R3-34]

+on:+ push:+ branches:+ - renovate/*++permissions:+ contents: read++jobs:+ pin:+ name: Repin Dependencies+ if: github.event.repository.fork == false+ uses: ./.github/workflows/bazel.yml+ with:+ name: Repin Dependencies+ run: |+ ./go all:pin+ ./go rust:pin+ ./go format+ artifact-name: repin-changes++ commit-repins:+ name: Commit Repins+ needs: pin+ permissions:+ contents: write+ actions: read+ uses: ./.github/workflows/commit-changes.yml+ with:+ artifact-name: repin-changes+ commit-message: "Repin dependencies"+
Evidence
The new workflow triggers on pushes to renovate/* and invokes the reusable commit workflow. That
reusable workflow force-pushes (git push --force) to the target branch, which can clobber newer
remote commits if another push lands while the run is executing; adding per-branch
concurrency/cancellation (and/or --force-with-lease) prevents these races.

.github/workflows/ci-renovate-rbe.yml[3-43]
.github/workflows/commit-changes.yml[46-59]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution
### Issue description
The new `CI - Renovate - RBE` workflow runs on every push to `renovate/*` and then executes a force-push back to the same branch (via `commit-changes.yml`). Without a per-branch concurrency group, overlapping runs for the same branch (e.g., Renovate pushes again while CI is running) can lead to:
- wasted CI on superseded heads
- or worse: the force-push overwriting newer Renovate commits
### Issue Context
- The workflow is `on: push` for `renovate/*`.
- It uses `commit-changes.yml`, which does `git push --force`.
### Fix Focus Areas
- Add workflow-level concurrency scoped to the branch ref to serialize/cancel runs:
- `.github/workflows/ci-renovate-rbe.yml[1-43]`
- Consider making the push safer by switching to `--force-with-lease` to avoid overwriting remote updates:
- `.github/workflows/commit-changes.yml[46-56]`

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Qodo Logo

@titusfortner
titusfortner merged commit 72a6efd into trunkMay 19, 2026
17 checks passed
@titusfortner
titusfortner deleted the dependency_workflows branch May 19, 2026 17:14
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

B-buildIncludes scripting, bazel and CI integrations

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@titusfortner@selenium-ci
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[build] remove overly complicated renovate workflow - #17525

Merged
titusfortner merged 2 commits into
trunkfrom
dependency_workflows
May 19, 2026
Merged

[build] remove overly complicated renovate workflow#17525
titusfortner merged 2 commits into
trunkfrom
dependency_workflows

Conversation

@titusfortner

Copy link
Copy Markdown
Member

🔗 Related Issues

#17504 was not a good approach (shocking I made it too complicated)
Turns out we can adjust renovate not to actually create PRs but just to create branches we can run tests against

💥 What does this PR do?

This is just to prove out the approach:

  • Renovate should create a single branch here
  • ci-renovate-rbe should kick off and run tests

🔧 Implementation Notes

This is the better alternative

🤖 AI assistance

  • No substantial AI assistance used
  • AI assisted (complete below)
    • Tool(s): claude
    • What was generated: json settings
    • I reviewed all AI output and can explain the change

💡 Additional Considerations

Follow on is to:

  • Decide on Auto merge (maybe break into major/minor)
  • expand to more than one branch at a time
  • manage failures

@selenium-ciselenium-ci added the B-build Includes scripting, bazel and CI integrations label May 19, 2026
@qodo-code-review

Copy link
Copy Markdown
Contributor

Review Summary by Qodo

Simplify dependency workflow with Renovate branch-based testing

✨ Enhancement

Grey Divider

Walkthroughs

Description
• Simplify dependency update workflow using Renovate's built-in branch creation
• Remove complex multi-step orchestration in favor of automatic branch-based testing
• Add new ci-renovate-rbe.yml workflow to test and commit dependency updates
• Update Renovate configuration to create branches instead of pull requests
Diagram
flowchart LR
A["Renovate creates<br/>renovate/* branches"] --> B["ci-renovate-rbe<br/>workflow triggers"]
B --> C["Repin dependencies<br/>and format"]
C --> D["Commit changes<br/>to branch"]
D --> E["Run RBE tests"]
E --> F["Run GitHub CI"]
Loading

Grey Divider

File Changes

1. .github/workflows/ci-rbe.yml ✨ Enhancement +2/-1

Add workflow_call trigger and remove renovate exclusion

• Add workflow_call trigger to allow reuse from other workflows
• Remove condition that excluded renovate branches from running tests
• Simplify job condition to only check for fork status

.github/workflows/ci-rbe.yml


2. .github/workflows/ci-renovate-rbe.yml ✨ Enhancement +43/-0

New workflow for testing renovate dependency branches

• New workflow triggered on renovate/* branch pushes
• Repin dependencies using ./go all:pin and ./go rust:pin
• Commit repins to branch and run full test suite
• Chain RBE tests and GitHub CI tests after successful commits

.github/workflows/ci-renovate-rbe.yml


3. .github/workflows/renovate-dependencies.yml ✨ Enhancement +0/-102

Remove overly complicated renovate orchestration workflow

• Completely removed complex orchestration workflow
• Eliminated manual branch reset and Renovate invocation logic
• Removed matrix-based major/minor dependency PR creation

.github/workflows/renovate-dependencies.yml


View more (2)
4. .github/workflows/renovate-dependency-pr.yml ✨ Enhancement +0/-106

Remove complex dependency PR creation workflow

• Completely removed workflow that created individual dependency PRs
• Eliminated branch detection and patch-based promotion logic
• Removed dependency on manual workflow orchestration

.github/workflows/renovate-dependency-pr.yml


5. renovate.json ⚙️ Configuration changes +3/-21

Configure Renovate for branch-based testing approach

• Set prCreation: "approval" to prevent automatic PR creation
• Add branchConcurrentLimit: 1 to limit concurrent dependency branches
• Remove dependencyDashboardApproval and automerge settings
• Update dashboard header to explain new branch-based workflow
• Remove orchestration-specific grouping rules for major/minor updates

renovate.json


Grey Divider

Qodo Logo

@qodo-code-review

qodo-code-reviewBot commented May 19, 2026

Copy link
Copy Markdown
Contributor

Code Review by Qodo

🐞 Bugs (1)📘 Rule violations (0)

Grey Divider


Remediation recommended

1. Force-push branch race 🐞 Bug☼ Reliability
Description
ci-renovate-rbe.yml triggers on push to renovate/* and then calls commit-changes.yml, which
force-pushes back to that same branch; without per-branch workflow concurrency this can overwrite
newer Renovate commits (or run CI on commits that are no longer the branch head). This is especially
risky if Renovate pushes additional commits to the branch while the workflow is still running.
Code

.github/workflows/ci-renovate-rbe.yml[R3-34]

+on:+ push:+ branches:+ - renovate/*++permissions:+ contents: read++jobs:+ pin:+ name: Repin Dependencies+ if: github.event.repository.fork == false+ uses: ./.github/workflows/bazel.yml+ with:+ name: Repin Dependencies+ run: |+ ./go all:pin+ ./go rust:pin+ ./go format+ artifact-name: repin-changes++ commit-repins:+ name: Commit Repins+ needs: pin+ permissions:+ contents: write+ actions: read+ uses: ./.github/workflows/commit-changes.yml+ with:+ artifact-name: repin-changes+ commit-message: "Repin dependencies"+
Evidence
The new workflow triggers on pushes to renovate/* and invokes the reusable commit workflow. That
reusable workflow force-pushes (git push --force) to the target branch, which can clobber newer
remote commits if another push lands while the run is executing; adding per-branch
concurrency/cancellation (and/or --force-with-lease) prevents these races.

.github/workflows/ci-renovate-rbe.yml[3-43]
.github/workflows/commit-changes.yml[46-59]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution
### Issue description
The new `CI - Renovate - RBE` workflow runs on every push to `renovate/*` and then executes a force-push back to the same branch (via `commit-changes.yml`). Without a per-branch concurrency group, overlapping runs for the same branch (e.g., Renovate pushes again while CI is running) can lead to:
- wasted CI on superseded heads
- or worse: the force-push overwriting newer Renovate commits
### Issue Context
- The workflow is `on: push` for `renovate/*`.
- It uses `commit-changes.yml`, which does `git push --force`.
### Fix Focus Areas
- Add workflow-level concurrency scoped to the branch ref to serialize/cancel runs:
- `.github/workflows/ci-renovate-rbe.yml[1-43]`
- Consider making the push safer by switching to `--force-with-lease` to avoid overwriting remote updates:
- `.github/workflows/commit-changes.yml[46-56]`

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Qodo Logo

@titusfortner
titusfortner merged commit 72a6efd into trunkMay 19, 2026
17 checks passed
@titusfortner
titusfortner deleted the dependency_workflows branch May 19, 2026 17:14
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

B-buildIncludes scripting, bazel and CI integrations

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@titusfortner@selenium-ci
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[build] remove overly complicated renovate workflow - #17525

Merged
titusfortner merged 2 commits into
trunkfrom
dependency_workflows
May 19, 2026
Merged

[build] remove overly complicated renovate workflow#17525
titusfortner merged 2 commits into
trunkfrom
dependency_workflows

Conversation

@titusfortner

Copy link
Copy Markdown
Member

🔗 Related Issues

#17504 was not a good approach (shocking I made it too complicated)
Turns out we can adjust renovate not to actually create PRs but just to create branches we can run tests against

💥 What does this PR do?

This is just to prove out the approach:

  • Renovate should create a single branch here
  • ci-renovate-rbe should kick off and run tests

🔧 Implementation Notes

This is the better alternative

🤖 AI assistance

  • No substantial AI assistance used
  • AI assisted (complete below)
    • Tool(s): claude
    • What was generated: json settings
    • I reviewed all AI output and can explain the change

💡 Additional Considerations

Follow on is to:

  • Decide on Auto merge (maybe break into major/minor)
  • expand to more than one branch at a time
  • manage failures

@selenium-ciselenium-ci added the B-build Includes scripting, bazel and CI integrations label May 19, 2026
@qodo-code-review

Copy link
Copy Markdown
Contributor

Review Summary by Qodo

Simplify dependency workflow with Renovate branch-based testing

✨ Enhancement

Grey Divider

Walkthroughs

Description
• Simplify dependency update workflow using Renovate's built-in branch creation
• Remove complex multi-step orchestration in favor of automatic branch-based testing
• Add new ci-renovate-rbe.yml workflow to test and commit dependency updates
• Update Renovate configuration to create branches instead of pull requests
Diagram
flowchart LR
A["Renovate creates<br/>renovate/* branches"] --> B["ci-renovate-rbe<br/>workflow triggers"]
B --> C["Repin dependencies<br/>and format"]
C --> D["Commit changes<br/>to branch"]
D --> E["Run RBE tests"]
E --> F["Run GitHub CI"]
Loading

Grey Divider

File Changes

1. .github/workflows/ci-rbe.yml ✨ Enhancement +2/-1

Add workflow_call trigger and remove renovate exclusion

• Add workflow_call trigger to allow reuse from other workflows
• Remove condition that excluded renovate branches from running tests
• Simplify job condition to only check for fork status

.github/workflows/ci-rbe.yml


2. .github/workflows/ci-renovate-rbe.yml ✨ Enhancement +43/-0

New workflow for testing renovate dependency branches

• New workflow triggered on renovate/* branch pushes
• Repin dependencies using ./go all:pin and ./go rust:pin
• Commit repins to branch and run full test suite
• Chain RBE tests and GitHub CI tests after successful commits

.github/workflows/ci-renovate-rbe.yml


3. .github/workflows/renovate-dependencies.yml ✨ Enhancement +0/-102

Remove overly complicated renovate orchestration workflow

• Completely removed complex orchestration workflow
• Eliminated manual branch reset and Renovate invocation logic
• Removed matrix-based major/minor dependency PR creation

.github/workflows/renovate-dependencies.yml


View more (2)
4. .github/workflows/renovate-dependency-pr.yml ✨ Enhancement +0/-106

Remove complex dependency PR creation workflow

• Completely removed workflow that created individual dependency PRs
• Eliminated branch detection and patch-based promotion logic
• Removed dependency on manual workflow orchestration

.github/workflows/renovate-dependency-pr.yml


5. renovate.json ⚙️ Configuration changes +3/-21

Configure Renovate for branch-based testing approach

• Set prCreation: "approval" to prevent automatic PR creation
• Add branchConcurrentLimit: 1 to limit concurrent dependency branches
• Remove dependencyDashboardApproval and automerge settings
• Update dashboard header to explain new branch-based workflow
• Remove orchestration-specific grouping rules for major/minor updates

renovate.json


Grey Divider

Qodo Logo

@qodo-code-review

qodo-code-reviewBot commented May 19, 2026

Copy link
Copy Markdown
Contributor

Code Review by Qodo

🐞 Bugs (1)📘 Rule violations (0)

Grey Divider


Remediation recommended

1. Force-push branch race 🐞 Bug☼ Reliability
Description
ci-renovate-rbe.yml triggers on push to renovate/* and then calls commit-changes.yml, which
force-pushes back to that same branch; without per-branch workflow concurrency this can overwrite
newer Renovate commits (or run CI on commits that are no longer the branch head). This is especially
risky if Renovate pushes additional commits to the branch while the workflow is still running.
Code

.github/workflows/ci-renovate-rbe.yml[R3-34]

+on:+ push:+ branches:+ - renovate/*++permissions:+ contents: read++jobs:+ pin:+ name: Repin Dependencies+ if: github.event.repository.fork == false+ uses: ./.github/workflows/bazel.yml+ with:+ name: Repin Dependencies+ run: |+ ./go all:pin+ ./go rust:pin+ ./go format+ artifact-name: repin-changes++ commit-repins:+ name: Commit Repins+ needs: pin+ permissions:+ contents: write+ actions: read+ uses: ./.github/workflows/commit-changes.yml+ with:+ artifact-name: repin-changes+ commit-message: "Repin dependencies"+
Evidence
The new workflow triggers on pushes to renovate/* and invokes the reusable commit workflow. That
reusable workflow force-pushes (git push --force) to the target branch, which can clobber newer
remote commits if another push lands while the run is executing; adding per-branch
concurrency/cancellation (and/or --force-with-lease) prevents these races.

.github/workflows/ci-renovate-rbe.yml[3-43]
.github/workflows/commit-changes.yml[46-59]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution
### Issue description
The new `CI - Renovate - RBE` workflow runs on every push to `renovate/*` and then executes a force-push back to the same branch (via `commit-changes.yml`). Without a per-branch concurrency group, overlapping runs for the same branch (e.g., Renovate pushes again while CI is running) can lead to:
- wasted CI on superseded heads
- or worse: the force-push overwriting newer Renovate commits
### Issue Context
- The workflow is `on: push` for `renovate/*`.
- It uses `commit-changes.yml`, which does `git push --force`.
### Fix Focus Areas
- Add workflow-level concurrency scoped to the branch ref to serialize/cancel runs:
- `.github/workflows/ci-renovate-rbe.yml[1-43]`
- Consider making the push safer by switching to `--force-with-lease` to avoid overwriting remote updates:
- `.github/workflows/commit-changes.yml[46-56]`

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Qodo Logo

@titusfortner
titusfortner merged commit 72a6efd into trunkMay 19, 2026
17 checks passed
@titusfortner
titusfortner deleted the dependency_workflows branch May 19, 2026 17:14
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

B-buildIncludes scripting, bazel and CI integrations

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@titusfortner@selenium-ci
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

[build] remove overly complicated renovate workflow - #17525

Merged
titusfortner merged 2 commits into
trunkfrom
dependency_workflows
May 19, 2026
Merged

[build] remove overly complicated renovate workflow#17525
titusfortner merged 2 commits into
trunkfrom
dependency_workflows

Conversation

@titusfortner

Copy link
Copy Markdown
Member

🔗 Related Issues

#17504 was not a good approach (shocking I made it too complicated)
Turns out we can adjust renovate not to actually create PRs but just to create branches we can run tests against

💥 What does this PR do?

This is just to prove out the approach:

  • Renovate should create a single branch here
  • ci-renovate-rbe should kick off and run tests

🔧 Implementation Notes

This is the better alternative

🤖 AI assistance

  • No substantial AI assistance used
  • AI assisted (complete below)
    • Tool(s): claude
    • What was generated: json settings
    • I reviewed all AI output and can explain the change

💡 Additional Considerations

Follow on is to:

  • Decide on Auto merge (maybe break into major/minor)
  • expand to more than one branch at a time
  • manage failures

@selenium-ciselenium-ci added the B-build Includes scripting, bazel and CI integrations label May 19, 2026
@qodo-code-review

Copy link
Copy Markdown
Contributor

Review Summary by Qodo

Simplify dependency workflow with Renovate branch-based testing

✨ Enhancement

Grey Divider

Walkthroughs

Description
• Simplify dependency update workflow using Renovate's built-in branch creation
• Remove complex multi-step orchestration in favor of automatic branch-based testing
• Add new ci-renovate-rbe.yml workflow to test and commit dependency updates
• Update Renovate configuration to create branches instead of pull requests
Diagram
flowchart LR
A["Renovate creates<br/>renovate/* branches"] --> B["ci-renovate-rbe<br/>workflow triggers"]
B --> C["Repin dependencies<br/>and format"]
C --> D["Commit changes<br/>to branch"]
D --> E["Run RBE tests"]
E --> F["Run GitHub CI"]
Loading

Grey Divider

File Changes

1. .github/workflows/ci-rbe.yml ✨ Enhancement +2/-1

Add workflow_call trigger and remove renovate exclusion

• Add workflow_call trigger to allow reuse from other workflows
• Remove condition that excluded renovate branches from running tests
• Simplify job condition to only check for fork status

.github/workflows/ci-rbe.yml


2. .github/workflows/ci-renovate-rbe.yml ✨ Enhancement +43/-0

New workflow for testing renovate dependency branches

• New workflow triggered on renovate/* branch pushes
• Repin dependencies using ./go all:pin and ./go rust:pin
• Commit repins to branch and run full test suite
• Chain RBE tests and GitHub CI tests after successful commits

.github/workflows/ci-renovate-rbe.yml


3. .github/workflows/renovate-dependencies.yml ✨ Enhancement +0/-102

Remove overly complicated renovate orchestration workflow

• Completely removed complex orchestration workflow
• Eliminated manual branch reset and Renovate invocation logic
• Removed matrix-based major/minor dependency PR creation

.github/workflows/renovate-dependencies.yml


View more (2)
4. .github/workflows/renovate-dependency-pr.yml ✨ Enhancement +0/-106

Remove complex dependency PR creation workflow

• Completely removed workflow that created individual dependency PRs
• Eliminated branch detection and patch-based promotion logic
• Removed dependency on manual workflow orchestration

.github/workflows/renovate-dependency-pr.yml


5. renovate.json ⚙️ Configuration changes +3/-21

Configure Renovate for branch-based testing approach

• Set prCreation: "approval" to prevent automatic PR creation
• Add branchConcurrentLimit: 1 to limit concurrent dependency branches
• Remove dependencyDashboardApproval and automerge settings
• Update dashboard header to explain new branch-based workflow
• Remove orchestration-specific grouping rules for major/minor updates

renovate.json


Grey Divider

Qodo Logo

@qodo-code-review

qodo-code-reviewBot commented May 19, 2026

Copy link
Copy Markdown
Contributor

Code Review by Qodo

🐞 Bugs (1)📘 Rule violations (0)

Grey Divider


Remediation recommended

1. Force-push branch race 🐞 Bug☼ Reliability
Description
ci-renovate-rbe.yml triggers on push to renovate/* and then calls commit-changes.yml, which
force-pushes back to that same branch; without per-branch workflow concurrency this can overwrite
newer Renovate commits (or run CI on commits that are no longer the branch head). This is especially
risky if Renovate pushes additional commits to the branch while the workflow is still running.
Code

.github/workflows/ci-renovate-rbe.yml[R3-34]

+on:+ push:+ branches:+ - renovate/*++permissions:+ contents: read++jobs:+ pin:+ name: Repin Dependencies+ if: github.event.repository.fork == false+ uses: ./.github/workflows/bazel.yml+ with:+ name: Repin Dependencies+ run: |+ ./go all:pin+ ./go rust:pin+ ./go format+ artifact-name: repin-changes++ commit-repins:+ name: Commit Repins+ needs: pin+ permissions:+ contents: write+ actions: read+ uses: ./.github/workflows/commit-changes.yml+ with:+ artifact-name: repin-changes+ commit-message: "Repin dependencies"+
Evidence
The new workflow triggers on pushes to renovate/* and invokes the reusable commit workflow. That
reusable workflow force-pushes (git push --force) to the target branch, which can clobber newer
remote commits if another push lands while the run is executing; adding per-branch
concurrency/cancellation (and/or --force-with-lease) prevents these races.

.github/workflows/ci-renovate-rbe.yml[3-43]
.github/workflows/commit-changes.yml[46-59]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution
### Issue description
The new `CI - Renovate - RBE` workflow runs on every push to `renovate/*` and then executes a force-push back to the same branch (via `commit-changes.yml`). Without a per-branch concurrency group, overlapping runs for the same branch (e.g., Renovate pushes again while CI is running) can lead to:
- wasted CI on superseded heads
- or worse: the force-push overwriting newer Renovate commits
### Issue Context
- The workflow is `on: push` for `renovate/*`.
- It uses `commit-changes.yml`, which does `git push --force`.
### Fix Focus Areas
- Add workflow-level concurrency scoped to the branch ref to serialize/cancel runs:
- `.github/workflows/ci-renovate-rbe.yml[1-43]`
- Consider making the push safer by switching to `--force-with-lease` to avoid overwriting remote updates:
- `.github/workflows/commit-changes.yml[46-56]`

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Qodo Logo

@titusfortner
titusfortner merged commit 72a6efd into trunkMay 19, 2026
17 checks passed
@titusfortner
titusfortner deleted the dependency_workflows branch May 19, 2026 17:14
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

B-buildIncludes scripting, bazel and CI integrations

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@titusfortner@selenium-ci