Skip to content

chore(renovate): unblock automated dependency updates - #1508

Merged
ryoppippi merged 2 commits into
mainfrom
chore/fix-renovate-auto-updates
Jul 28, 2026
Merged

ryoppippi merged 2 commits into
mainfrom
chore/fix-renovate-auto-updates

Conversation

@ryoppippi

@ryoppippi ryoppippi commented Jul 28, 2026 •

Copy link
Copy Markdown
Member

Summary

Renovate has not opened a dependency PR since 2026-06-22. Nothing is broken on our side except the schedule: every pending update is gated behind the schedule:weekly window (before 3am on monday) that came in through the shared preset, and no hosted run has landed inside that window for five weeks.

Evidence, from a local renovate --dry-run=full --platform=github ccusage/ccusage:

  • unmodified config: result: "done", onboarded: true, zero branches — the run is healthy, it just is not allowed to do anything today.
  • with the schedule dropped: 25 update branches plus lock file maintenance pending, i.e. a five-week backlog.

What Changed

.github/renovate.json now inlines the settings that used to come from github>ryoppippi/renovate-config:no-group. That preset lives outside this org, and the settings that need to differ here are exactly the ones that caused the outage, so extending it no longer buys anything. Everything else from the preset is carried over verbatim: config:recommended, automerge, platformAutomerge, branchConcurrentLimit: 0, labels, minimumReleaseAge: 3 days, postUpdateOptions: [pnpmDedupe], rangeStrategy: bump, and the security label on vulnerability alerts.

Differences against the preset:

  • no schedule:weekly, so any hosted run can act on the backlog.
  • dependencyDashboard: true. It is the only place the hosted app reports config errors, and the only way to trigger a run by hand — with it disabled this outage was completely invisible.
  • lockFileMaintenance runs at any time instead of weekly, so flake.lock, pnpm-lock.yaml and rust/Cargo.lock refresh as soon as inputs move rather than once a week.

nix.enabled stays on — the manager is off by default, and it is what puts flake.lock in the lock file maintenance branch at all.

Also fixes nix/git-hooks.nix: the renovate-config-validator hook ran renovate --strict config-validator, which exits with unknown option '--strict' on renovate 43. config-validator is not a subcommand, and --strict only exists on the standalone renovate-config-validator binary. The hook only fires when a renovate config file is staged, so nobody hit it before.

Testing

  • renovate-config-validator --strict passes, and the fixed hook ran it on this commit.
  • Dry-run with the new settings forced: the backlog is created immediately, the lock file maintenance branch is included, and the Dependency Dashboard issue would be created.

Notes

  • Lock file maintenance rewrites flake.lock as a whole, so it also moves the litellm and models-dev pricing inputs. update-pricing.yaml already runs hourly and regenerates the committed pricing snapshots from whatever revision is locked, so a snapshot left behind by a lock maintenance PR is repaired within the hour.
  • A flake.lock bump that changes a formatter version makes security & lint preflight fail on treefmt-check and needs a nix fmt commit on the branch. That is what kept chore(deps): lock file maintenance #1355 red and open for a month. Renovate cannot do that itself: postUpgradeTasks commands have to match the global allowedCommands allowlist, which only Mend controls on the hosted app.

Follow-up after merge

Pushing this to main triggers a webhook run. If the Dependency Dashboard issue does not appear within ~15 minutes, the hosted app is not processing this repository at all — most likely fallout from the ryoppippi/ccusage to ccusage/ccusage transfer — and it needs re-onboarding from https://developer.mend.io/github/ccusage/ccusage (or by toggling the app's repository access).


View with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is enabled.


Summary by cubic

Unblocks automated dependency updates by inlining and adjusting renovate config to remove the weekly schedule gate and enable the Dependency Dashboard. Also fixes the nix git hook to use the standalone renovate-config-validator.

  • Refactors

    • Inline github>ryoppippi/renovate-config:no-group and remove schedule:weekly so hosted runs can create PRs anytime.
    • Enable dependencyDashboard and run lockfile maintenance “at any time” for flake.lock, pnpm-lock.yaml, and rust/Cargo.lock.
    • Preserve previous behavior: automerge, platformAutomerge, branchConcurrentLimit: 0, labels, minimumReleaseAge: "3 days", postUpdateOptions: ["pnpmDedupe"], rangeStrategy: "bump", security labels, and nix.enabled: true.
  • Bug Fixes

    • Update Nix hook to call ${pkgs.renovate}/bin/renovate-config-validator --strict (previous renovate --strict config-validator was invalid and failed).

Written for commit 4f4ebb8. Summary will update on new commits.

Review in cubic

`renovate --strict config-validator` exits with "unknown option '--strict'"
on renovate 43: `config-validator` is not a subcommand, and `--strict` only
exists on the separate `renovate-config-validator` binary. The hook only
runs when a renovate config file is staged, which is why the breakage went
unnoticed.
Renovate has not opened a PR since 2026-06-22 even though the app is
installed org-wide and the config validates. A local `renovate
--dry-run=full` against ccusage/ccusage finishes with result "done" and 25
pending updates, all of them held back by the `schedule:weekly` window
(`before 3am on monday`) that came in through the shared preset: unless a
hosted run happens to land inside that window, nothing is ever created.

The preset is now inlined instead of extended. ryoppippi/renovate-config
lives outside this org, and the two settings that need to differ here are
exactly the ones that caused the outage, so tracking the preset no longer
buys anything.

Changes against the inlined preset:

- no `schedule:weekly`, so any hosted run can act on the backlog
- `dependencyDashboard` enabled: it is the only place the hosted app
  reports config errors and the only way to trigger a run by hand, and with
  it disabled this outage was completely invisible
- `lockFileMaintenance` runs at any time rather than weekly, so flake.lock,
  pnpm-lock.yaml and rust/Cargo.lock refresh as soon as inputs move

`nix.enabled` stays on: the manager is off by default, and it is what keeps
flake.lock in the lock file maintenance branch at all.
Copilot AI review requested due to automatic review settings July 28, 2026 00:48
@pullfrog

pullfrog Bot commented Jul 28, 2026 •

Copy link
Copy Markdown
Contributor

This run was cancelled 🛑

The workflow was cancelled before completion. Please check the link below for details.

Pullfrog  | View workflow run | via Pullfrog | 𝕏

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
ccusage-guide 4f4ebb8 Commit Preview URL

Branch Preview URL
Jul 28 2026, 12:43 AM

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@coderabbitai

coderabbitai Bot commented Jul 28, 2026 •

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: f52aa45c-eca2-491f-a1c1-2a5a59bbe6f0

📥 Commits

Reviewing files that changed from the base of the PR and between 1dab5c2 and 4f4ebb8.

📒 Files selected for processing (2)
  • .github/renovate.json
  • nix/git-hooks.nix

📝 Walkthrough

Walkthrough

Renovate configuration now uses the recommended preset with explicit update policies, while the Nix pre-commit hook invokes the standalone strict configuration validator.

Changes

Renovate tooling

Layer / File(s) Summary
Renovate policy configuration
.github/renovate.json
Extends the recommended Renovate configuration and adds Nix, automerge, concurrency, dashboard, lockfile, release-age, pnpm deduplication, range, and labeling settings.
Strict validator hook
nix/git-hooks.nix
Changes the pre-commit hook to run renovate-config-validator --strict directly and documents the corrected invocation.

Estimated code review effort: 2 (Simple) | ~10 minutes

Suggested reviewers: copilot

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/fix-renovate-auto-updates

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@ryoppippi
ryoppippi merged commit 61f80bc into main Jul 28, 2026
11 of 12 checks passed
@ryoppippi
ryoppippi deleted the chore/fix-renovate-auto-updates branch July 28, 2026 00:48
@github-actions

Copy link
Copy Markdown
Contributor

ccusage performance comparison

PR SHA: 4f4ebb8de04f
Base SHA: 1dab5c2afcf3

This compares the Rust PR release binary against the configured base package on the same CI runner.

Package runtime diagnostics

Compares the PR package wrapper, the installed native optional dependency binary, and the workspace release binary on the same large fixture. This identifies whether slow package results come from JavaScript wrapper overhead, the published native binary build, or the Rust core itself.

Fixtures: Claude /home/runner/_work/_temp/ccusage-large-fixture (1.01 GiB, 2597 files), Codex /home/runner/_work/_temp/ccusage-large-codex-fixture (1.01 GiB, 2597 files)
All rows run --offline --json, measured by hyperfine with 0 warmups and 1 runs. This isolates wrapper overhead from the installed native optional dependency and the workspace release binary built on the runner.

Command Runtime Input Median Throughput Samples
claude --offline --json Package wrapper 1.01 GiB 379.3ms 2.65 GiB/s 1
claude --offline --json Installed native binary 1.01 GiB 305.9ms 3.29 GiB/s 1
codex --offline --json Package wrapper 1.01 GiB 118.3ms 8.51 GiB/s 1
codex --offline --json Installed native binary 1.01 GiB 92.1ms 10.93 GiB/s 1

Committed fixture performance

Committed small fixtures for stable PR-to-PR feedback and explicit Claude/Codex command coverage.

Fixtures: Claude apps/ccusage/test/fixtures/claude (0.00 MiB, 2 files), Codex apps/ccusage/test/fixtures/codex (0.00 MiB, 1 files)
Base runs the published ccusage package from pkg.pr.new, installed before measurement; PR runs the published native ccusage binary from pkg.pr.new, installed before measurement. Both run --offline --json, measured by hyperfine with 2 warmups and 7 runs.
Peak RSS is measured separately with /usr/bin/time using 1 runs. Lower RSS ratios are better.

Command Input Base median PR median PR vs base Base peak RSS PR peak RSS PR/base RSS Base throughput PR throughput
claude daily --offline --json 0.00 MiB 29.0ms 4.7ms 6.23x 55.00 MiB 12.45 MiB 0.23x 0.05 MiB/s 0.33 MiB/s
claude session --offline --json 0.00 MiB 25.5ms 3.5ms 7.27x 55.00 MiB 12.44 MiB 0.23x 0.06 MiB/s 0.44 MiB/s
codex daily --offline --json 0.00 MiB 24.9ms 2.3ms 10.60x 55.25 MiB 10.45 MiB 0.19x 0.03 MiB/s 0.37 MiB/s
codex session --offline --json 0.00 MiB 26.8ms 2.3ms 11.54x 55.25 MiB 10.45 MiB 0.19x 0.03 MiB/s 0.37 MiB/s

Large real-world-shaped fixture performance

Generated fixtures shaped from aggregate local log statistics: thousands of JSONL files, many small sessions, and a long tail of larger sessions. No real prompts, paths, or outputs are stored in the fixtures.

Fixtures: Claude /home/runner/_work/_temp/ccusage-large-fixture (1.01 GiB, 2597 files), Codex /home/runner/_work/_temp/ccusage-large-codex-fixture (1.01 GiB, 2597 files)
Base runs the published ccusage package from pkg.pr.new, installed before measurement; PR runs the published native ccusage binary from pkg.pr.new, installed before measurement. Both run --offline --json, measured by hyperfine with 0 warmups and 1 runs.
Peak RSS is measured separately with /usr/bin/time using 1 runs. Lower RSS ratios are better.

Command Input Base median PR median PR vs base Base peak RSS PR peak RSS PR/base RSS Base throughput PR throughput
claude --offline --json 1.01 GiB 365.9ms 328.3ms 1.11x 944.58 MiB 924.57 MiB 0.98x 2.75 GiB/s 3.07 GiB/s
codex --offline --json 1.01 GiB 114.3ms 92.9ms 1.23x 412.65 MiB 410.64 MiB 1.00x 8.80 GiB/s 10.83 GiB/s

Artifact size

Artifact Base PR Delta Ratio
packed ccusage-*.tgz 18.78 KiB 18.78 KiB +0.00 KiB 1.00x
installed native package binary 4156.78 KiB 4156.78 KiB +0.00 KiB 1.00x

Lower medians and smaller artifacts are better. CI runner noise still applies; use same-run ratios as directional PR feedback, not release guarantees.

@github-actions

Copy link
Copy Markdown
Contributor

ccusage performance comparison

PR SHA: 4f4ebb8de04f
Base SHA: 1dab5c2afcf3

This compares the PR package against the configured base package on the same CI runner.

Package runtime diagnostics

Compares the PR package wrapper, the installed native optional dependency binary, and the workspace release binary on the same large fixture. This identifies whether slow package results come from JavaScript wrapper overhead, the published native binary build, or the Rust core itself.

Fixtures: Claude /home/runner/_work/_temp/ccusage-large-fixture (1.01 GiB, 2597 files), Codex /home/runner/_work/_temp/ccusage-large-codex-fixture (1.01 GiB, 2597 files)
All rows run --offline --json, measured by hyperfine with 0 warmups and 1 runs. This isolates wrapper overhead from the installed native optional dependency and the workspace release binary built on the runner.

Command Runtime Input Median Throughput Samples
claude --offline --json Package wrapper 1.01 GiB 359.0ms 2.80 GiB/s 1
claude --offline --json Installed native binary 1.01 GiB 311.1ms 3.24 GiB/s 1
codex --offline --json Package wrapper 1.01 GiB 114.1ms 8.83 GiB/s 1
codex --offline --json Installed native binary 1.01 GiB 94.7ms 10.63 GiB/s 1

Committed fixture performance

Committed small fixtures for stable PR-to-PR feedback and explicit Claude/Codex command coverage.

Fixtures: Claude apps/ccusage/test/fixtures/claude (0.00 MiB, 2 files), Codex apps/ccusage/test/fixtures/codex (0.00 MiB, 1 files)
Base runs the published ccusage package from pkg.pr.new, installed before measurement; PR runs the published ccusage package from pkg.pr.new, installed before measurement. Both run --offline --json, measured by hyperfine with 2 warmups and 7 runs.
Peak RSS is measured separately with /usr/bin/time using 1 runs. Lower RSS ratios are better.

Command Input Base median PR median PR vs base Base peak RSS PR peak RSS PR/base RSS Base throughput PR throughput
claude daily --offline --json 0.00 MiB 27.6ms 29.1ms 0.95x 55.00 MiB 55.00 MiB 1.00x 0.06 MiB/s 0.05 MiB/s
claude session --offline --json 0.00 MiB 26.0ms 24.3ms 1.07x 55.25 MiB 55.00 MiB 1.00x 0.06 MiB/s 0.06 MiB/s
codex daily --offline --json 0.00 MiB 24.4ms 24.8ms 0.99x 55.00 MiB 54.75 MiB 1.00x 0.04 MiB/s 0.03 MiB/s
codex session --offline --json 0.00 MiB 22.5ms 24.3ms 0.93x 55.00 MiB 55.25 MiB 1.00x 0.04 MiB/s 0.04 MiB/s

Large real-world-shaped fixture performance

Generated fixtures shaped from aggregate local log statistics: thousands of JSONL files, many small sessions, and a long tail of larger sessions. No real prompts, paths, or outputs are stored in the fixtures.

Fixtures: Claude /home/runner/_work/_temp/ccusage-large-fixture (1.01 GiB, 2597 files), Codex /home/runner/_work/_temp/ccusage-large-codex-fixture (1.01 GiB, 2597 files)
Base runs the published ccusage package from pkg.pr.new, installed before measurement; PR runs the published ccusage package from pkg.pr.new, installed before measurement. Both run --offline --json, measured by hyperfine with 0 warmups and 1 runs.
Peak RSS is measured separately with /usr/bin/time using 1 runs. Lower RSS ratios are better.

Command Input Base median PR median PR vs base Base peak RSS PR peak RSS PR/base RSS Base throughput PR throughput
claude --offline --json 1.01 GiB 369.9ms 344.3ms 1.07x 952.58 MiB 928.57 MiB 0.97x 2.72 GiB/s 2.92 GiB/s
codex --offline --json 1.01 GiB 113.3ms 136.1ms 0.83x 434.64 MiB 416.64 MiB 0.96x 8.88 GiB/s 7.40 GiB/s

Artifact size

Artifact Base PR Delta Ratio
packed ccusage-*.tgz 18.78 KiB 18.78 KiB +0.00 KiB 1.00x
installed native package binary 4156.78 KiB 4156.78 KiB +0.00 KiB 1.00x

Lower medians and smaller artifacts are better. CI runner noise still applies; use same-run ratios as directional PR feedback, not release guarantees.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants