Repository navigation
chore(renovate): unblock automated dependency updates - #1508
Conversation
`renovate --strict config-validator` exits with "unknown option '--strict'" on renovate 43: `config-validator` is not a subcommand, and `--strict` only exists on the separate `renovate-config-validator` binary. The hook only runs when a renovate config file is staged, which is why the breakage went unnoticed.
Renovate has not opened a PR since 2026-06-22 even though the app is installed org-wide and the config validates. A local `renovate --dry-run=full` against ccusage/ccusage finishes with result "done" and 25 pending updates, all of them held back by the `schedule:weekly` window (`before 3am on monday`) that came in through the shared preset: unless a hosted run happens to land inside that window, nothing is ever created. The preset is now inlined instead of extended. ryoppippi/renovate-config lives outside this org, and the two settings that need to differ here are exactly the ones that caused the outage, so tracking the preset no longer buys anything. Changes against the inlined preset: - no `schedule:weekly`, so any hosted run can act on the backlog - `dependencyDashboard` enabled: it is the only place the hosted app reports config errors and the only way to trigger a run by hand, and with it disabled this outage was completely invisible - `lockFileMaintenance` runs at any time rather than weekly, so flake.lock, pnpm-lock.yaml and rust/Cargo.lock refresh as soon as inputs move `nix.enabled` stays on: the manager is off by default, and it is what keeps flake.lock in the lock file maintenance branch at all.
|
This run was cancelled 🛑 The workflow was cancelled before completion. Please check the link below for details. |
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
ccusage-guide | 4f4ebb8 | Commit Preview URL Branch Preview URL |
Jul 28 2026, 12:43 AM |
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
📝 WalkthroughWalkthroughRenovate configuration now uses the recommended preset with explicit update policies, while the Nix pre-commit hook invokes the standalone strict configuration validator. ChangesRenovate tooling
Estimated code review effort: 2 (Simple) | ~10 minutes Suggested reviewers: ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
ccusage performance comparisonPR SHA: This compares the Rust PR release binary against the configured base package on the same CI runner. Package runtime diagnosticsCompares the PR package wrapper, the installed native optional dependency binary, and the workspace release binary on the same large fixture. This identifies whether slow package results come from JavaScript wrapper overhead, the published native binary build, or the Rust core itself. Fixtures: Claude
Committed fixture performanceCommitted small fixtures for stable PR-to-PR feedback and explicit Claude/Codex command coverage. Fixtures: Claude
Large real-world-shaped fixture performanceGenerated fixtures shaped from aggregate local log statistics: thousands of JSONL files, many small sessions, and a long tail of larger sessions. No real prompts, paths, or outputs are stored in the fixtures. Fixtures: Claude
Artifact size
Lower medians and smaller artifacts are better. CI runner noise still applies; use same-run ratios as directional PR feedback, not release guarantees. |
ccusage performance comparisonPR SHA: This compares the PR package against the configured base package on the same CI runner. Package runtime diagnosticsCompares the PR package wrapper, the installed native optional dependency binary, and the workspace release binary on the same large fixture. This identifies whether slow package results come from JavaScript wrapper overhead, the published native binary build, or the Rust core itself. Fixtures: Claude
Committed fixture performanceCommitted small fixtures for stable PR-to-PR feedback and explicit Claude/Codex command coverage. Fixtures: Claude
Large real-world-shaped fixture performanceGenerated fixtures shaped from aggregate local log statistics: thousands of JSONL files, many small sessions, and a long tail of larger sessions. No real prompts, paths, or outputs are stored in the fixtures. Fixtures: Claude
Artifact size
Lower medians and smaller artifacts are better. CI runner noise still applies; use same-run ratios as directional PR feedback, not release guarantees. |

Summary
Renovate has not opened a dependency PR since 2026-06-22. Nothing is broken on our side except the schedule: every pending update is gated behind the
schedule:weeklywindow (before 3am on monday) that came in through the shared preset, and no hosted run has landed inside that window for five weeks.Evidence, from a local
renovate --dry-run=full --platform=github ccusage/ccusage:result: "done",onboarded: true, zero branches — the run is healthy, it just is not allowed to do anything today.What Changed
.github/renovate.jsonnow inlines the settings that used to come fromgithub>ryoppippi/renovate-config:no-group. That preset lives outside this org, and the settings that need to differ here are exactly the ones that caused the outage, so extending it no longer buys anything. Everything else from the preset is carried over verbatim:config:recommended,automerge,platformAutomerge,branchConcurrentLimit: 0,labels,minimumReleaseAge: 3 days,postUpdateOptions: [pnpmDedupe],rangeStrategy: bump, and thesecuritylabel on vulnerability alerts.Differences against the preset:
schedule:weekly, so any hosted run can act on the backlog.dependencyDashboard: true. It is the only place the hosted app reports config errors, and the only way to trigger a run by hand — with it disabled this outage was completely invisible.lockFileMaintenanceruns at any time instead of weekly, soflake.lock,pnpm-lock.yamlandrust/Cargo.lockrefresh as soon as inputs move rather than once a week.nix.enabledstays on — the manager is off by default, and it is what putsflake.lockin the lock file maintenance branch at all.Also fixes
nix/git-hooks.nix: therenovate-config-validatorhook ranrenovate --strict config-validator, which exits withunknown option '--strict'on renovate 43.config-validatoris not a subcommand, and--strictonly exists on the standalonerenovate-config-validatorbinary. The hook only fires when a renovate config file is staged, so nobody hit it before.Testing
renovate-config-validator --strictpasses, and the fixed hook ran it on this commit.Notes
flake.lockas a whole, so it also moves thelitellmandmodels-devpricing inputs.update-pricing.yamlalready runs hourly and regenerates the committed pricing snapshots from whatever revision is locked, so a snapshot left behind by a lock maintenance PR is repaired within the hour.flake.lockbump that changes a formatter version makessecurity & lint preflightfail ontreefmt-checkand needs anix fmtcommit on the branch. That is what kept chore(deps): lock file maintenance #1355 red and open for a month. Renovate cannot do that itself:postUpgradeTaskscommands have to match the globalallowedCommandsallowlist, which only Mend controls on the hosted app.Follow-up after merge
Pushing this to
maintriggers a webhook run. If the Dependency Dashboard issue does not appear within ~15 minutes, the hosted app is not processing this repository at all — most likely fallout from theryoppippi/ccusagetoccusage/ccusagetransfer — and it needs re-onboarding from https://developer.mend.io/github/ccusage/ccusage (or by toggling the app's repository access).Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is enabled.Summary by cubic
Unblocks automated dependency updates by inlining and adjusting
renovateconfig to remove the weekly schedule gate and enable the Dependency Dashboard. Also fixes thenixgit hook to use the standalonerenovate-config-validator.Refactors
github>ryoppippi/renovate-config:no-groupand removeschedule:weeklyso hosted runs can create PRs anytime.dependencyDashboardand run lockfile maintenance “at any time” forflake.lock,pnpm-lock.yaml, andrust/Cargo.lock.automerge,platformAutomerge,branchConcurrentLimit: 0, labels,minimumReleaseAge: "3 days",postUpdateOptions: ["pnpmDedupe"],rangeStrategy: "bump", security labels, andnix.enabled: true.Bug Fixes
${pkgs.renovate}/bin/renovate-config-validator --strict(previousrenovate --strict config-validatorwas invalid and failed).Written for commit 4f4ebb8. Summary will update on new commits.