Skip to content

feat(renovate): digest=commit manager; retire registry-specific rules#99

Merged
cplieger merged 2 commits into
mainfrom
registry-commit-pins
Jul 22, 2026
Merged

feat(renovate): digest=commit manager; retire registry-specific rules#99
cplieger merged 2 commits into
mainfrom
registry-commit-pins

Conversation

@cplieger

Copy link
Copy Markdown
Owner

Adds the generic digest=commit customManager for codeload-tarball tag+commit pin pairs (documented in ci-renovate.md), fixes the nerd-fonts recompute template's double-v, and removes the mise/aqua manual-sha-bump rules plus the registry group/retag rules whose consumers left the app images (cplieger/tool-catalog publishes the compiled catalog daily; the toolbelt engine refreshes at runtime). Validated with renovate-config-validator.

cplieger added 2 commits July 22, 2026 15:07
Add a digest=commit customManager: a github-tags renovate comment
followed by an ARG *_REF=<tag> + ARG *_COMMIT=<sha> pair auto-updates
both lines (the digest resolves to the tag's dereferenced commit), so
the vibekit / web-terminal-kiro registry pins bump with no manual step.
Retire the mise/aqua manual-sha-bump rules it replaces, group the two
registries into one PR per repo, and gate digest-only updates (a moved
tag with no version bump = a retag) no-automerge with a security label,
matching the git-cliff asset-swap rule. Also fix the nerd-fonts
recompute command in prBodyNotes, which double-prefixed the tag's v and
would have hashed a 404.
…nalization

The mise/aqua pins left the app images (cplieger/tool-catalog publishes
the compiled catalog daily; the toolbelt engine refreshes at runtime),
so the tool-registries group rule and the registry retag gate have no
deps to match. The generic digest=commit customManager stays as the
documented mechanism for future codeload-tarball pins.
@cplieger
cplieger merged commit 5fd6ca7 into main Jul 22, 2026
12 checks passed
@cplieger
cplieger deleted the registry-commit-pins branch July 22, 2026 16:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant