Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Configure Renovate #535

Merged
merged 1 commit into from
Jul 26, 2023
Merged

Configure Renovate #535

merged 1 commit into from
Jul 26, 2023

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jul 25, 2023

Mend Renovate

Welcome to Renovate! This is an onboarding PR to help you understand and configure settings before regular Pull Requests begin.

🚦 To activate Renovate, merge this Pull Request. To disable Renovate, simply close this Pull Request unmerged.


Detected Package Files

  • compose-files/docker-compose.yml (docker-compose)
  • docker/Dockerfile-api (dockerfile)
  • docker/Dockerfile-workers (dockerfile)
  • docker/message_broker/Dockerfile (dockerfile)
  • .github/workflows/build.yml (github-actions)
  • .github/workflows/build_on_tag.api.yml (github-actions)
  • .github/workflows/run_tox.yml (github-actions)
  • docs/requirements.txt (pip_requirements)
  • requirements-test.txt (pip_requirements)
  • requirements.txt (pip_requirements)
  • .python-version (pyenv)

Configuration Summary

Based on the default config's presets, Renovate will:

  • Start dependency updates only once this onboarding PR is merged
  • Show all Merge Confidence badges for pull requests.
  • Enable Renovate Dependency Dashboard creation.
  • Use semantic commit type fix for dependencies and chore for all others if semantic commits are in use.
  • Ignore node_modules, bower_components, vendor and various test/tests directories.
  • Group known monorepo packages together.
  • Use curated list of recommended non-monorepo package groupings.
  • Apply crowd-sourced package replacement rules.
  • Apply crowd-sourced workarounds for known problems with packages.

🔡 Would you like to change the way Renovate is upgrading your dependencies? Simply edit the renovate.json in this branch with your custom config and the list of Pull Requests in the "What to Expect" section below will be updated the next time Renovate runs.


What to Expect

With your current configuration, Renovate will create 82 Pull Requests:

Update dependency requests to v2.31.0 [SECURITY]
  • Branch name: renovate/pypi-requests-vulnerability
  • Merge into: master
  • Upgrade requests to ==2.31.0
Update dependency certifi to v2023 [SECURITY]
  • Branch name: renovate/pypi-certifi-vulnerability
  • Merge into: master
  • Upgrade certifi to ==2023.7.22
Update dependency cryptography to v41 [SECURITY]
  • Branch name: renovate/pypi-cryptography-vulnerability
  • Merge into: master
  • Upgrade cryptography to ==41.0.2
Update dependency deprecated to v1.2.14
  • Schedule: ["at any time"]
  • Branch name: renovate/deprecated-1.x
  • Merge into: master
  • Upgrade deprecated to ==1.2.14
Update dependency flask-sqlalchemy to v3.0.5
  • Schedule: ["at any time"]
  • Branch name: renovate/flask-sqlalchemy-3.x
  • Merge into: master
  • Upgrade flask-sqlalchemy to ==3.0.5
Update dependency grpcio to v1.56.2
  • Schedule: ["at any time"]
  • Branch name: renovate/grpcio-1.x
  • Merge into: master
  • Upgrade grpcio to ==1.56.2
Update dependency mako to v1.2.4
  • Schedule: ["at any time"]
  • Branch name: renovate/mako-1.x
  • Merge into: master
  • Upgrade mako to ==1.2.4
Update dependency markupsafe to v2.1.3
  • Schedule: ["at any time"]
  • Branch name: renovate/markupsafe-2.x
  • Merge into: master
  • Upgrade markupsafe to ==2.1.3
Update dependency prompt-toolkit to v3.0.39
  • Schedule: ["at any time"]
  • Branch name: renovate/prompt-toolkit-3.x
  • Merge into: master
  • Upgrade prompt-toolkit to ==3.0.39
Update dependency psycopg2-binary to v2.9.6
  • Schedule: ["at any time"]
  • Branch name: renovate/psycopg2-binary-2.x
  • Merge into: master
  • Upgrade psycopg2-binary to ==2.9.6
Update dependency python-dateutil to v2.8.2
  • Schedule: ["at any time"]
  • Branch name: renovate/python-dateutil-2.x
  • Merge into: master
  • Upgrade python-dateutil to ==2.8.2
Update dependency ruamel-yaml-clib to v0.2.7
  • Schedule: ["at any time"]
  • Branch name: renovate/ruamel-yaml-clib-0.x
  • Merge into: master
  • Upgrade ruamel-yaml-clib to ==0.2.7
Update dependency sqlalchemy to v2.0.19
  • Schedule: ["at any time"]
  • Branch name: renovate/sqlalchemy-2.x
  • Merge into: master
  • Upgrade sqlalchemy to ==2.0.19
Update dependency tomli to v1.2.3
  • Schedule: ["at any time"]
  • Branch name: renovate/tomli-1.x
  • Merge into: master
  • Upgrade tomli to ==1.2.3
Update dependency urllib3 to v1.26.16
  • Schedule: ["at any time"]
  • Branch name: renovate/urllib3-1.x
  • Merge into: master
  • Upgrade urllib3 to ==1.26.16
Update dependency wcwidth to v0.2.6
  • Schedule: ["at any time"]
  • Branch name: renovate/wcwidth-0.x
  • Merge into: master
  • Upgrade wcwidth to ==0.2.6
Update dependency alembic to v1.11.1
  • Schedule: ["at any time"]
  • Branch name: renovate/alembic-1.x
  • Merge into: master
  • Upgrade alembic to ==1.11.1
Update dependency amqp to v5.1.1
  • Schedule: ["at any time"]
  • Branch name: renovate/amqp-5.x
  • Merge into: master
  • Upgrade amqp to ==5.1.1
Update dependency backoff to v1.11.1
  • Schedule: ["at any time"]
  • Branch name: renovate/backoff-1.x
  • Merge into: master
  • Upgrade backoff to ==1.11.1
Update dependency boto3 to v1.28.11
  • Schedule: ["at any time"]
  • Branch name: renovate/boto3-1.x
  • Merge into: master
  • Upgrade boto3 to ==1.28.11
Update dependency botocore to v1.31.11
  • Schedule: ["at any time"]
  • Branch name: renovate/botocore-1.x
  • Merge into: master
  • Upgrade botocore to ==1.31.11
Update dependency celery to v5.3.1
  • Schedule: ["at any time"]
  • Branch name: renovate/celery-5.x
  • Merge into: master
  • Upgrade celery to ==5.3.1
Update dependency charset-normalizer to v2.1.1
  • Schedule: ["at any time"]
  • Branch name: renovate/charset-normalizer-2.x
  • Merge into: master
  • Upgrade charset-normalizer to ==2.1.1
Update dependency click to v8.1.6
  • Schedule: ["at any time"]
  • Branch name: renovate/click-8.x
  • Merge into: master
  • Upgrade click to ==8.1.6
Update dependency click-repl to v0.3.0
  • Schedule: ["at any time"]
  • Branch name: renovate/click-repl-0.x
  • Merge into: master
  • Upgrade click-repl to ==0.3.0
Update dependency coverage to v6.5.0
  • Schedule: ["at any time"]
  • Branch name: renovate/coverage-6.x
  • Merge into: master
  • Upgrade coverage to ==6.5.0
Update dependency dogpile-cache to v1.2.2
  • Schedule: ["at any time"]
  • Branch name: renovate/dogpile-cache-1.x
  • Merge into: master
  • Upgrade dogpile-cache to ==1.2.2
Update dependency exceptiongroup to v1.1.2
  • Schedule: ["at any time"]
  • Branch name: renovate/exceptiongroup-1.x
  • Merge into: master
  • Upgrade exceptiongroup to ==1.1.2
Update dependency flask to v2.3.2
  • Schedule: ["at any time"]
  • Branch name: renovate/flask-2.x
  • Merge into: master
  • Upgrade flask to ==2.3.2
Update dependency googleapis-common-protos to v1.59.1
  • Schedule: ["at any time"]
  • Branch name: renovate/googleapis-common-protos-1.x
  • Merge into: master
  • Upgrade googleapis-common-protos to ==1.59.1
Update dependency idna to v2.10
  • Schedule: ["at any time"]
  • Branch name: renovate/idna-2.x
  • Merge into: master
  • Upgrade idna to ==2.10
Update dependency importlib-metadata to v6.8.0
  • Schedule: ["at any time"]
  • Branch name: renovate/importlib-metadata-6.x
  • Merge into: master
  • Upgrade importlib-metadata to ==6.8.0
Update dependency importlib-resources to v5.13.0
  • Schedule: ["at any time"]
  • Branch name: renovate/importlib-resources-5.x
  • Merge into: master
  • Upgrade importlib-resources to ==5.13.0
Update dependency iniconfig to v1.1.1
  • Schedule: ["at any time"]
  • Branch name: renovate/iniconfig-1.x
  • Merge into: master
  • Upgrade iniconfig to ==1.1.1
Update dependency itsdangerous to v2.1.2
  • Schedule: ["at any time"]
  • Branch name: renovate/itsdangerous-2.x
  • Merge into: master
  • Upgrade itsdangerous to ==2.1.2
Update dependency jinja2 to v3.1.2
  • Schedule: ["at any time"]
  • Branch name: renovate/jinja2-3.x
  • Merge into: master
  • Upgrade jinja2 to ==3.1.2
Update dependency kombu to v5.3.1
  • Schedule: ["at any time"]
  • Branch name: renovate/kombu-5.x
  • Merge into: master
  • Upgrade kombu to ==5.3.1
Update dependency krb5 to v0.5.0
  • Schedule: ["at any time"]
  • Branch name: renovate/krb5-0.x
  • Merge into: master
  • Upgrade krb5 to ==0.5.0
Update dependency opentelemetry-api to v1.19.0
  • Schedule: ["at any time"]
  • Branch name: renovate/opentelemetry-api-1.x
  • Merge into: master
  • Upgrade opentelemetry-api to ==1.19.0
Update dependency opentelemetry-exporter-otlp to v1.19.0
  • Schedule: ["at any time"]
  • Branch name: renovate/opentelemetry-exporter-otlp-1.x
  • Merge into: master
  • Upgrade opentelemetry-exporter-otlp to ==1.19.0
Update dependency opentelemetry-exporter-otlp-proto-grpc to v1.19.0
  • Schedule: ["at any time"]
  • Branch name: renovate/opentelemetry-exporter-otlp-proto-grpc-1.x
  • Merge into: master
  • Upgrade opentelemetry-exporter-otlp-proto-grpc to ==1.19.0
Update dependency opentelemetry-exporter-otlp-proto-http to v1.19.0
  • Schedule: ["at any time"]
  • Branch name: renovate/opentelemetry-exporter-otlp-proto-http-1.x
  • Merge into: master
  • Upgrade opentelemetry-exporter-otlp-proto-http to ==1.19.0
Update dependency opentelemetry-proto to v1.19.0
  • Schedule: ["at any time"]
  • Branch name: renovate/opentelemetry-proto-1.x
  • Merge into: master
  • Upgrade opentelemetry-proto to ==1.19.0
Update dependency opentelemetry-sdk to v1.19.0
  • Schedule: ["at any time"]
  • Branch name: renovate/opentelemetry-sdk-1.x
  • Merge into: master
  • Upgrade opentelemetry-sdk to ==1.19.0
Update dependency pbr to v5.11.1
  • Schedule: ["at any time"]
  • Branch name: renovate/pbr-5.x
  • Merge into: master
  • Upgrade pbr to ==5.11.1
Update dependency pycparser to v2.21
  • Schedule: ["at any time"]
  • Branch name: renovate/pycparser-2.x
  • Merge into: master
  • Upgrade pycparser to ==2.21
Update dependency pyparsing to v3.1.0
  • Schedule: ["at any time"]
  • Branch name: renovate/pyparsing-3.x
  • Merge into: master
  • Upgrade pyparsing to ==3.1.0
Update dependency pyspnego to v0.9.1
  • Schedule: ["at any time"]
  • Branch name: renovate/pyspnego-0.x
  • Merge into: master
  • Upgrade pyspnego to ==0.9.1
Update dependency pytest to v7.4.0
  • Schedule: ["at any time"]
  • Branch name: renovate/pytest-7.x
  • Merge into: master
  • Upgrade pytest to ==7.4.0
Update dependency python-qpid-proton to v0.38.0
  • Schedule: ["at any time"]
  • Branch name: renovate/python-qpid-proton-0.x
  • Merge into: master
  • Upgrade python-qpid-proton to ==0.38.0
Update dependency ruamel-yaml to v0.17.32
  • Schedule: ["at any time"]
  • Branch name: renovate/ruamel-yaml-0.x
  • Merge into: master
  • Upgrade ruamel-yaml to ==0.17.32
Update dependency s3transfer to v0.6.1
  • Schedule: ["at any time"]
  • Branch name: renovate/s3transfer-0.x
  • Merge into: master
  • Upgrade s3transfer to ==0.6.1
Update dependency six to v1.16.0
  • Schedule: ["at any time"]
  • Branch name: renovate/six-1.x
  • Merge into: master
  • Upgrade six to ==1.16.0
Update dependency stevedore to v3.5.2
  • Schedule: ["at any time"]
  • Branch name: renovate/stevedore-3.x
  • Merge into: master
  • Upgrade stevedore to ==3.5.2
Update dependency tenacity to v8.2.2
  • Schedule: ["at any time"]
  • Branch name: renovate/tenacity-8.x
  • Merge into: master
  • Upgrade tenacity to ==8.2.2
Update dependency typing-extensions to v4.7.1
  • Schedule: ["at any time"]
  • Branch name: renovate/typing-extensions-4.x
  • Merge into: master
  • Upgrade typing-extensions to ==4.7.1
Update dependency werkzeug to v2.3.6
  • Schedule: ["at any time"]
  • Branch name: renovate/werkzeug-2.x
  • Merge into: master
  • Upgrade werkzeug to ==2.3.6
Update dependency wrapt to v1.15.0
  • Schedule: ["at any time"]
  • Branch name: renovate/wrapt-1.x
  • Merge into: master
  • Upgrade wrapt to ==1.15.0
Update dependency zipp to v3.16.2
  • Schedule: ["at any time"]
  • Branch name: renovate/zipp-3.x
  • Merge into: master
  • Upgrade zipp to ==3.16.2
Update python Docker tag to v3.11.4
  • Schedule: ["at any time"]
  • Branch name: renovate/python-3.x
  • Merge into: master
  • Upgrade python to 3.11.4
Update rabbitmq Docker tag to v3.12
  • Schedule: ["at any time"]
  • Branch name: renovate/rabbitmq-3.x
  • Merge into: master
  • Upgrade rabbitmq to 3.12-management
Update redhat-actions/push-to-registry action to v2.7.1
Update dependency attrs to v23
  • Schedule: ["at any time"]
  • Branch name: renovate/attrs-23.x
  • Merge into: master
  • Upgrade attrs to ==23.1.0
Update dependency backoff to v2
  • Schedule: ["at any time"]
  • Branch name: renovate/backoff-2.x
  • Merge into: master
  • Upgrade backoff to ==2.2.1
Update dependency billiard to v4
  • Schedule: ["at any time"]
  • Branch name: renovate/billiard-4.x
  • Merge into: master
  • Upgrade billiard to ==4.1.0
Update dependency charset-normalizer to v3
  • Schedule: ["at any time"]
  • Branch name: renovate/charset-normalizer-3.x
  • Merge into: master
  • Upgrade charset-normalizer to ==3.2.0
Update dependency coverage to v7
  • Schedule: ["at any time"]
  • Branch name: renovate/coverage-7.x
  • Merge into: master
  • Upgrade coverage to ==7.2.7
Update dependency decorator to v5
  • Schedule: ["at any time"]
  • Branch name: renovate/decorator-5.x
  • Merge into: master
  • Upgrade decorator to ==5.1.1
Update dependency idna to v3
  • Schedule: ["at any time"]
  • Branch name: renovate/idna-3.x
  • Merge into: master
  • Upgrade idna to ==3.4
Update dependency importlib-resources to v6
  • Schedule: ["at any time"]
  • Branch name: renovate/importlib-resources-6.x
  • Merge into: master
  • Upgrade importlib-resources to ==6.0.0
Update dependency iniconfig to v2
  • Schedule: ["at any time"]
  • Branch name: renovate/iniconfig-2.x
  • Merge into: master
  • Upgrade iniconfig to ==2.0.0
Update dependency jmespath to v1
  • Schedule: ["at any time"]
  • Branch name: renovate/jmespath-1.x
  • Merge into: master
  • Upgrade jmespath to ==1.0.1
Update dependency operator-manifest to v2
  • Schedule: ["at any time"]
  • Branch name: renovate/operator-manifest-2.x
  • Merge into: master
  • Upgrade operator-manifest to ==2.0.1
Update dependency packaging to v23
  • Schedule: ["at any time"]
  • Branch name: renovate/packaging-23.x
  • Merge into: master
  • Upgrade packaging to ==23.1
Update dependency pluggy to v1
  • Schedule: ["at any time"]
  • Branch name: renovate/pluggy-1.x
  • Merge into: master
  • Upgrade pluggy to ==1.2.0
Update dependency pytest-cov to v4
  • Schedule: ["at any time"]
  • Branch name: renovate/pytest-cov-4.x
  • Merge into: master
  • Upgrade pytest-cov to ==4.1.0
Update dependency pytz to v2023
  • Schedule: ["at any time"]
  • Branch name: renovate/pytz-2023.x
  • Merge into: master
  • Upgrade pytz to ==2023.3
Update dependency sphinx to v7
  • Schedule: ["at any time"]
  • Branch name: renovate/sphinx-7.x
  • Merge into: master
  • Upgrade sphinx to ==7.1.0
Update dependency stevedore to v5
  • Schedule: ["at any time"]
  • Branch name: renovate/stevedore-5.x
  • Merge into: master
  • Upgrade stevedore to ==5.1.0
Update dependency tomli to v2
  • Schedule: ["at any time"]
  • Branch name: renovate/tomli-2.x
  • Merge into: master
  • Upgrade tomli to ==2.0.1
Update dependency urllib3 to v2
  • Schedule: ["at any time"]
  • Branch name: renovate/urllib3-2.x
  • Merge into: master
  • Upgrade urllib3 to ==2.0.4
Update postgres Docker tag to v15
  • Schedule: ["at any time"]
  • Branch name: renovate/postgres-15.x
  • Merge into: master
  • Upgrade postgres to 15.3

🚸 Branch creation will be limited to maximum 2 per hour, so it doesn't swamp any CI resources or overwhelm the project. See docs for prhourlylimit for details.


❓ Got questions? Check out Renovate's Docs, particularly the Getting Started section.
If you need any further assistance then you can also request help here.


This PR has been generated by Mend Renovate. View repository job log here.

@xDaile
Copy link
Contributor

xDaile commented Jul 25, 2023

Would it make sense to update the dependencies first? Just to avoid creating 83 PRs as mentioned above?

@yashvardhannanavati
Copy link
Collaborator

yashvardhannanavati commented Jul 25, 2023

Would it make sense to update the dependencies first? Just to avoid creating 83 PRs as mentioned above?

In order to not overwhelm the CI, it will be creating those PRs two per hour and at one given instance, it will only have a max of 10 PRs open. So I think we can leave it to renovate bot to update those deps one at a time. That will also help us ensure that we are not breaking IIB with those updates.

Here's where it gets the default value from : https://docs.renovatebot.com/configuration-options/#prconcurrentlimit

@zanssa
Copy link
Contributor

zanssa commented Jul 25, 2023

Just wondering if we should not use the automatic configuration and make some adjustment here? I see it is only detecting docker-compose file and I believe we need to have the same images in both compose files unless I am missing something.

Also, would it help if we group a couple of pkgs in one MR instead of having a separate MR for each pkg so we will have lower num of MRs? wdyt? This might help https://docs.renovatebot.com/configuration-options/#matchpackagepatterns

@yashvardhannanavati
Copy link
Collaborator

Just wondering if we should not use the automatic configuration and make some adjustment here? I see it is only detecting docker-compose file and I believe we need to have the same images in both compose files unless I am missing something.

Yes, this PR is from renovatebot to enable itself. We will make improvements like having it detect podman-compose.yml too after it is active.

Also, would it help if we group a couple of pkgs in one MR instead of having a separate MR for each pkg so we will have lower num of MRs? wdyt? This might help https://docs.renovatebot.com/configuration-options/#matchpackagepatterns

For this, I personally think we should have separate MR for each package unless they're dependent on each other like pyspnego and krb5, which I think renovate bot should take care of by itself. If it doesn't we can group those together.

Copy link
Contributor

@chandwanitulsi chandwanitulsi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1 on enabling it.
we will need to configure it in future PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants