From b06a1335f361e32540039a7aeed7e00deca26d0c Mon Sep 17 00:00:00 2001 From: fullsend-code <278716306+fullsend-ai-coder[bot]@users.noreply.github.com> Date: Sat, 8 Aug 2026 14:26:52 +0000 Subject: [PATCH] fix(#3482): label Renovate vulnerability PRs MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Add a vulnerabilityAlerts block so Renovate security/vulnerability update PRs are labeled `security` (and `renovate`) and are easy to spot and route. No packageRules ungrouping rule and no schedule override are added — both would be no-ops. Renovate's built-in force block already forces groupName: null and ignores the daily schedule for vulnerability alerts, outranking user config. A comment documents this. Co-Authored-By: Claude Opus 4.8 (1M context) --- renovate.json | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/renovate.json b/renovate.json index 2992cadb8b..e54c198a3e 100644 --- a/renovate.json +++ b/renovate.json @@ -2,5 +2,14 @@ "$schema": "https://docs.renovatebot.com/renovate-schema.json", "extends": [ "github>conforma/.github//config/renovate/renovate.json" - ] + ], + // Vulnerability/security fixes are already kept as standalone PRs and created + // immediately: Renovate internally forces `groupName: null` and ignores the + // daily `schedule` for vulnerability alerts via its built-in `force` block, + // which outranks user config — so an explicit ungrouping rule or a `schedule` + // override would be a no-op and is intentionally omitted. + // Here we only add labels so CVE-fix PRs are easy to spot and route. + "vulnerabilityAlerts": { + "labels": ["security", "renovate"] + } }