Summary
Roll out the proposed hybrid dependency-management policy after ADR 0012 and the shared renovate-config.json are accepted and merged to main. Renovate will own routine version updates; GitHub Dependabot will retain dependency graph alerts and security update pull requests.
Merge gate
Blocked until the .github policy/configuration change containing ADR 0012, renovate-config.json, and runbooks/dependency-management.md is merged. Do not remove a repository's .github/dependabot.yml before the shared preset is available on main.
Scope
The Renovate GitHub App is installed for all organization repositories and is not suspended. Migrate the currently known workspace repositories that contain .github/dependabot.yml:
z-shell/.github is migrated atomically in the policy/configuration change itself.
Per-repository checklist
Triage
- Suggested item type: Maintenance
- Priority: High
- Effort: Medium
- Status: Blocked pending policy/config merge
References
decisions/0012-hybrid-dependency-management.md
runbooks/dependency-management.md
renovate-config.json
Summary
Roll out the proposed hybrid dependency-management policy after ADR 0012 and the shared
renovate-config.jsonare accepted and merged tomain. Renovate will own routine version updates; GitHub Dependabot will retain dependency graph alerts and security update pull requests.Merge gate
Blocked until the
.githubpolicy/configuration change containing ADR 0012,renovate-config.json, andrunbooks/dependency-management.mdis merged. Do not remove a repository's.github/dependabot.ymlbefore the shared preset is available onmain.Scope
The Renovate GitHub App is installed for all organization repositories and is not suspended. Migrate the currently known workspace repositories that contain
.github/dependabot.yml:z-shell/z-a-meta-pluginsz-shell/srcz-shell/ziz-shell/wikiz-shell/zdz-shell/zsh-ezaz-shell/zsh-lintz-shell/zunitz-shell/.githubis migrated atomically in the policy/configuration change itself.Per-repository checklist
local>z-shell/.github:renovate-configor automatic organization preset discovery.renovate.jsononly when an exception is required.z-shell/zicurrently requiresbaseBranches: ["next"]..github/dependabot.ymlso routine version updates do not overlap.renovate-config-validator.Triage
References
decisions/0012-hybrid-dependency-management.mdrunbooks/dependency-management.mdrenovate-config.json