Skip to content

Rework Renovate config, drop third-party extension installer, tidy CI - #467

Merged
alcohol merged 6 commits into
mainfrom
repo-maintenance
Oct 8, 2026
Merged

alcohol merged 6 commits into
mainfrom
repo-maintenance

Conversation

@alcohol

@alcohol alcohol commented Oct 8, 2026

Copy link
Copy Markdown
Member

Repository maintenance, split into one commit per area so each can be reviewed (or reverted) on its own.

Commits

Rework Renovate config and drop Dependabot

  • Remove dependabot.yml: Renovate already manages GitHub Actions and the two were opening competing PRs (e.g. 8bc612c vs a737876). Dependabot security alerts are a repo setting and are unaffected.
  • Group non-major action updates into one PR with a 7 day minimumReleaseAge (replaces the Dependabot cooldown); each action PR otherwise triggers 3 workflows × 8 platforms
  • Drop rebaseWhen: behind-base-branch (default auto) to avoid redundant multi-arch rebuilds
  • Remove no-op rules (enabled: true, dependencyDashboardApproval: false)
  • Scope separateMinorPatch to composer/composer
  • Pin 2.2 to patch releases with a single allowedVersions: "<2.3.0" rule
  • Merge the two identical custom managers, anchor/escape the path pattern, accept -RC versions
  • Add a PR note for a new Composer major on latest/ (stackbrew aliases, LTS directory)
  • Don't propose PHP major base image bumps for 1.10 and 2.2
  • Add helpers:pinGitHubActionDigests

Validated with renovate-config-validator --strict.

Build bz2 and zip with docker-php-ext-install
Both extensions are bundled with php-src, so the base image can build them itself. This removes the third-party docker-php-extension-installer download and its manually maintained sha512. Verified locally (amd64) for all three images: php -m identical to before, ZipArchive/bzip2 round-trip works, images ~11MB smaller. Other platforms are exercised by this PR's CI.

Fix zizmor coverage and tidy build workflows

  • zizmor only triggered on .github/**.yml, so the .yaml build workflows and composite action were never scanned; rename to zizmor.yaml and match both extensions
  • Pass the metadata-action labels to build-push-action (they were computed but unused)
  • Rewrite manifest creation without unquoted command substitution / variable printf formats (SC2046, SC2059)
  • Document the $/ self-repository action reference

Describe the Renovate-driven release flow in README

Make generate-stackbrew-library.sh ShellCheck-clean
Explicit arrays instead of implicit word-splitting; no longer excluded from the ShellCheck workflow. Generated output verified byte-identical.

Extract manifest list creation into a composite action
The loop was duplicated for full/bin images in all three workflows; it now lives in .github/actions/create-manifest-list (dry-run verified to produce the same imagetools commands).

Note

The merge job only runs on main, so the composite action is first exercised on the first push after merging. Worth watching that run (or triggering via workflow_dispatch).

🤖 Generated with Claude Code

alcohol and others added 6 commits October 8, 2026 15:25
- Remove dependabot.yml; Renovate already manages GitHub Actions and the
  two were opening competing PRs
- Group non-major action updates with a 7 day release age (replaces the
  Dependabot cooldown)
- Drop rebaseWhen so the default applies (fewer redundant multi-arch runs)
- Remove no-op rules (enabled: true, dependencyDashboardApproval: false)
- Scope separateMinorPatch to composer/composer
- Pin 2.2 to patch releases with allowedVersions
- Merge the two identical custom managers, anchor/escape the path pattern,
  accept -RC versions
- Add a PR note for a new Composer major on latest
- Don't propose PHP major base image bumps for 1.10 and 2.2
- Add helpers:pinGitHubActionDigests

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Both extensions are bundled with php-src, so the base image can build
them itself. This drops the third-party docker-php-extension-installer
download (and its manually maintained sha512).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- zizmor only triggered on .github/**.yml, so the .yaml build workflows
  and composite action were never scanned; rename to zizmor.yaml and
  match both extensions
- Pass the metadata-action labels to build-push-action (they were
  computed but unused)
- Rewrite manifest creation with arrays instead of unquoted command
  substitution / variable printf formats (SC2046, SC2059)
- Document the $/ self-repository action reference

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Replace implicit word-splitting with explicit arrays (mapfile/read -a)
and stop excluding the script from the ShellCheck workflow. Generated
output is unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The same loop was repeated for the full and binary-only images in all
three build workflows. Move it to .github/actions/create-manifest-list
and call it via the $/ self-repository reference, which works without a
checkout in the merge job.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@alcohol
alcohol requested a balanced review from Copilot October 8, 2026 14:34
@alcohol
alcohol merged commit d4b2b58 into main Oct 8, 2026
34 checks passed
@alcohol
alcohol deleted the repo-maintenance branch October 8, 2026 14:39

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The new registry-publishing composite action cannot execute in pull-request CI and will first be exercised after merging.

0 open findings

What changed in this PR

Modernizes dependency automation, simplifies PHP extension builds, and consolidates multi-platform image publishing workflows.

Changes:

  • Reworks Renovate configuration and removes Dependabot.
  • Builds bundled PHP extensions directly and improves shell tooling.
  • Consolidates manifest publishing into a composite action and updates CI metadata/security coverage.
File Description
README.md Documents the Renovate-driven release flow.
latest/​Dockerfile Builds bundled bz2 and zip extensions directly.
2.2/​Dockerfile Builds bundled bz2 and zip extensions directly.
1.10/​Dockerfile Builds bundled bz2 and zip extensions directly.
generate-stackbrew-library.sh Replaces implicit word splitting with arrays.
.github/​workflows/​zizmor.yaml Extends scanning to YAML files.
.github/​workflows/​shellcheck.yaml ShellChecks every shell script safely.
.github/​workflows/​latest.yaml Adds labels and uses shared manifest creation.
.github/​workflows/​2.2.yaml Adds labels and uses shared manifest creation.
.github/​workflows/​1.10.yaml Adds labels and uses shared manifest creation.
.github/​renovate.json Refines dependency grouping and version policies.
.github/​dependabot.yml Removes competing dependency automation.
.github/​actions/​create-manifest-list/​action.yaml Introduces shared multi-platform manifest publishing.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants