From 2489bac00cb0db4df2c130d3752c75f48d36275d Mon Sep 17 00:00:00 2001 From: Oscar Wellner Date: Fri, 25 Sep 2026 20:19:21 +0200 Subject: [PATCH 1/3] build: configure renovate Extend the shared preset dnd-mapp/renovate-config at v1.0.0. Renovate merges its own minor and patch updates once the checks pass, so the contributing guide no longer says that a maintainer merges bot pull requests. The tool versions now point to devEngines instead of repeating them, so they cannot go stale. --- CONTRIBUTING.md | 8 +++----- renovate.json | 4 ++++ 2 files changed, 7 insertions(+), 5 deletions(-) create mode 100644 renovate.json diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index a667d2d..75ee7b1 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -10,10 +10,7 @@ Open an [issue](https://github.com/dnd-mapp/config-commitlint/issues) to discuss ## Development setup -The required tool versions are enforced through `devEngines` and `engineStrict`, so installing with other versions fails. - -- Node `24.21.0` -- pnpm `12.5.1` +The required Node and pnpm versions are set in `devEngines` in `package.json`. They are enforced through `engineStrict`, so installing with other versions fails. Install the dependencies with: @@ -134,7 +131,8 @@ Write the description in the imperative mood, such as "add scope rule". Mark a b - Update the changelog and README in the same pull request. - Use a title that follows the commit convention. - If you have write access, turn on auto-merge once the pull request is open, with `gh pr merge --auto --merge` or the "Enable auto-merge" button. It then merges as soon as it is approved and the checks pass. -- If auto-merge is off, the author merges the pull request once it is approved and the checks pass. A maintainer merges pull requests opened by a bot or by a contributor without write access. +- If auto-merge is off, the author merges the pull request once it is approved and the checks pass. A maintainer merges pull requests opened by a contributor without write access. +- Renovate merges its own minor and patch pull requests once the checks pass. A maintainer approves a major update from Renovate and turns on auto-merge for it. - Update the branch when it falls behind `main`, because auto-merge waits until the branch is up to date. The update dismisses the approval, so the pull request needs a new review. ## License diff --git a/renovate.json b/renovate.json new file mode 100644 index 0000000..d9099f1 --- /dev/null +++ b/renovate.json @@ -0,0 +1,4 @@ +{ + "$schema": "https://docs.renovatebot.com/renovate-schema.json", + "extends": ["github>dnd-mapp/renovate-config#v1.0.0"] +} From be9e96cc93ba0eb18ef8fa5a389d2e921d3f7e26 Mon Sep 17 00:00:00 2001 From: Oscar Wellner Date: Fri, 25 Sep 2026 20:19:24 +0200 Subject: [PATCH 2/3] build: allow minor updates of runtime dependencies Declare the runtime dependencies of the published package with caret ranges, so consumers get their minor releases without waiting for a new release of this package. --- CHANGELOG.md | 4 ++++ pnpm-lock.yaml | 2 +- pnpm-workspace.yaml | 2 +- 3 files changed, 6 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 4f45c8a..59ba59b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,6 +6,10 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), ## [Unreleased] +### Changed + +- `@commitlint/config-conventional` is now declared with a caret range instead of a tilde range. Consumers get its minor releases without waiting for a new release of this package. + ## [1.0.0] - 2026-09-21 ### Added diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 8384a4e..1ce7116 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -169,7 +169,7 @@ catalogs: specifier: ~21.2.2 version: 21.2.2 '@commitlint/config-conventional': - specifier: ~21.2.2 + specifier: ^21.2.2 version: 21.2.2 '@commitlint/lint': specifier: ~21.2.2 diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml index 2f816c9..0de6d93 100644 --- a/pnpm-workspace.yaml +++ b/pnpm-workspace.yaml @@ -30,7 +30,7 @@ catalog: catalogs: commitlint: "@commitlint/cli": ~21.2.2 - "@commitlint/config-conventional": ~21.2.2 + "@commitlint/config-conventional": ^21.2.2 "@commitlint/lint": ~21.2.2 "@commitlint/load": ~21.2.2 "@commitlint/types": ~21.2.0 From 3da5f284b739cca618a012734d3286d900fbfc7d Mon Sep 17 00:00:00 2001 From: Oscar Wellner Date: Fri, 25 Sep 2026 20:20:23 +0200 Subject: [PATCH 3/3] ci: lint the workflows with actionlint Run actionlint in the CI checks with the same pinned version as action-verify-release and renovate-config. The config declares the ubuntu-26.04 runner label, which actionlint does not know yet. --- .github/actionlint.yaml | 3 +++ .github/actions/ci/action.yaml | 8 +++++++- CONTRIBUTING.md | 5 ++++- 3 files changed, 14 insertions(+), 2 deletions(-) create mode 100644 .github/actionlint.yaml diff --git a/.github/actionlint.yaml b/.github/actionlint.yaml new file mode 100644 index 0000000..3c0c0e6 --- /dev/null +++ b/.github/actionlint.yaml @@ -0,0 +1,3 @@ +self-hosted-runner: + labels: + - ubuntu-26.04 diff --git a/.github/actions/ci/action.yaml b/.github/actions/ci/action.yaml index fded587..35ce8e5 100644 --- a/.github/actions/ci/action.yaml +++ b/.github/actions/ci/action.yaml @@ -1,5 +1,5 @@ name: CI checks -description: Installs dependencies, checks formatting, lints Markdown and code, type checks, tests, and builds +description: Installs dependencies, checks formatting, lints Markdown and code, type checks, builds, tests, and lints workflows runs: using: composite @@ -34,3 +34,9 @@ runs: - name: Test shell: bash run: pnpm run test-ci + + - name: Lint workflows + uses: raven-actions/actionlint@3d39aea434753780c3b3d4a1a31c854b4dbf49d7 # v2.2.0 + with: + version: 1.7.12 + pyflakes: false diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 75ee7b1..55c33ac 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -22,6 +22,8 @@ Dependency versions live in the catalogs in `pnpm-workspace.yaml`, which uses `c Newly published releases are held back for three days through `minimumReleaseAge`. You may need to wait before you can bump to a very recent version. +Install [actionlint](https://github.com/rhysd/actionlint) to lint the workflows locally, for example with `brew install actionlint`. CI runs the version that `.github/actions/ci/action.yaml` pins. + ## Git hooks [Lefthook](https://lefthook.dev/) installs the Git hooks when you run `pnpm install`. The hooks are defined in `lefthook.yaml`. @@ -51,7 +53,7 @@ When you add or change a rule, update the "Rules" section of the README in the s Tests use Vitest and load the config with `@commitlint/load` and `@commitlint/lint`. Add a test for every rule that you add or change. Coverage must stay above the thresholds in `vitest.config.ts`. -Check and format the repository with these commands. CI runs `format-check`, `lint-md`, `lint-ts`, `typecheck`, `test-ci`, and `build`. Run them yourself before you open a pull request. +Check and format the repository with these commands. CI runs `format-check`, `lint-md`, `lint-ts`, `typecheck`, `test-ci`, `build`, and actionlint. Run them yourself before you open a pull request. ```bash pnpm run format-check @@ -61,6 +63,7 @@ pnpm run lint-ts pnpm run typecheck pnpm run test-ci pnpm run build +actionlint ``` The `lint-md` script lints the Markdown files with markdownlint, and the `lint-ts` script lints the code with ESLint. Use `pnpm test` to run the tests in watch mode with the Vitest UI.