Commit Graph
2 Commits
Author SHA1 Message Date
2430927b40 ci(renovate): enable Dockerfile manager for the HTTP Gitea registry
Build ErsatzTV Image / Build & test (.NET) (push) Successful in 2m8s
Build ErsatzTV Image / Build & push image (amd64) (push) Successful in 3m41s
Turn on the `dockerfile` manager so Renovate also proposes base-image bumps for
docker/Dockerfile (mcr.microsoft.com/dotnet/* and our internal
192.168.1.95:3000/timothy/ersatztv-ffmpeg). The internal registry is HTTP-only,
so the workflow passes a host rule (insecureRegistry + registry read creds reused
from REGISTRY_USER/REGISTRY_PASSWORD) via RENOVATE_HOST_RULES — kept in the
workflow env, not in the committed renovate.json.

- Scope: only the built amd64 docker/Dockerfile; the vestigial upstream
  arm32v7/arm64/ffmpeg-tests Dockerfiles (archived ghcr base) are disabled.
- Group mcr.microsoft.com/dotnet/* base images into one PR.
- Compose files are build-only (no image tags) -> docker-compose manager not needed.

refs server-management#484

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-27 00:18:47 +00:00
a5cbf0fbf7 ci: add self-hosted Renovate (NuGet CPM + Gitea Actions)
Build ErsatzTV Image / Build & test (.NET) (push) Successful in 1m59s
Build ErsatzTV Image / Build & push image (amd64) (push) Successful in 3m32s
Stand up Renovate for this repo via a scheduled Gitea Actions workflow on the
shared act_runner. Managers: nuget (Central Package Management) + github-actions.
Dockerfile/docker-compose managers deferred until the HTTP Gitea-registry
handling is verified.

- renovate.json: config:recommended, dependency dashboard, OSV vulnerability
  alerts, family grouping (Microsoft.Extensions/AspNetCore/EF Core/Serilog/
  Refit/Lucene.Net), and patch-level auto-merge scoped to test/dev-only packages
  (NUnit/NSubstitute/Shouldly/coverlet/Test.Sdk/Testably/threading analyzer).
- .gitea/workflows/renovate.yml: weekly cron + workflow_dispatch (defaults to a
  safe dry run); bot identity + tokens from repo Actions secrets.

Supersedes the *proposing* half that dependency-scan.yml (ersatztv#14) left out;
the scan stays as a cheap in-repo detector for now.

refs server-management#484

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-26 23:38:58 +00:00