From 360f35d946924d25054a2006b61a1d8ba07bf494 Mon Sep 17 00:00:00 2001 From: MK Date: Wed, 7 Oct 2026 15:46:23 +0800 Subject: [PATCH] chore: exclude upstream-managed dependencies from Renovate --- .github/renovate.json | 174 +++++++++++++++++++++++++++++++++++++++++- 1 file changed, 172 insertions(+), 2 deletions(-) diff --git a/.github/renovate.json b/.github/renovate.json index 6094e39d65..30e9d887af 100644 --- a/.github/renovate.json +++ b/.github/renovate.json @@ -24,7 +24,7 @@ ], "packageRules": [ { - "description": "Ignore upstream toolchain npm packages (vendored via sync-remote or bumped by the proactive catalog workflow); everything else stays enabled so security alerts get fixed.", + "description": "Ignore toolchain npm packages managed by .github/workflows/upgrade-deps.yml through upgrade-deps.ts and sync-remote. Official Vitest packages share the runner version; the independently versioned @vitest/browser-webdriverio remains enabled.", "matchManagers": ["npm"], "matchPackageNames": [ "rolldown", @@ -34,7 +34,20 @@ "@tsdown/css", "@tsdown/exe", "@vitejs/devtools", + "@vitest/browser", + "@vitest/browser-playwright", + "@vitest/browser-preview", + "@vitest/coverage-istanbul", + "@vitest/coverage-v8", + "@vitest/mocker", + "@vitest/pretty-format", + "@vitest/snapshot", + "@vitest/spy", + "@vitest/ui", + "@vitest/utils", + "@vitest/web-worker", "lightningcss", + "lint-staged", "oxfmt", "oxlint", "oxlint-tsgolint", @@ -46,11 +59,168 @@ "enabled": false }, { - "description": "Ignore oxc crate updates (bumped by the proactive catalog workflow); other cargo crates stay enabled.", + "description": "Ignore oxc crate updates synchronized with Rolldown by .github/workflows/upgrade-deps.yml.", "matchManagers": ["cargo"], "matchPackageNames": ["/^oxc([_-].*)?$/"], "enabled": false }, + { + "description": "Ignore root catalog dependencies imported from rolldown/pnpm-workspace.yaml and vite/pnpm-workspace.yaml by sync-remote in .github/workflows/upgrade-deps.yml. Keep this list aligned with the upstream catalogs; independent package.json dependencies remain enabled.", + "matchManagers": ["npm"], + "matchFileNames": ["pnpm-workspace.yaml"], + "matchPackageNames": [ + "@babel/core", + "@babel/preset-env", + "@babel/preset-typescript", + "@emnapi/core", + "@emnapi/runtime", + "@jridgewell/trace-mapping", + "@napi-rs/cli", + "@napi-rs/wasm-runtime", + "@pnpm/find-workspace-packages", + "@rolldown/pluginutils", + "@rollup/plugin-commonjs", + "@rollup/plugin-node-resolve", + "@types/babel__core", + "@types/connect", + "@types/fs-extra", + "@types/lodash-es", + "@types/node", + "@types/semver", + "@types/serve-static", + "@types/ws", + "acorn", + "astring", + "cac", + "chalk", + "change-case", + "connect", + "consola", + "dedent", + "diff", + "emnapi", + "esbuild", + "estree-toolkit", + "execa", + "fast-glob", + "follow-redirects", + "fresh-import", + "fs-extra", + "glob", + "lodash-es", + "micromatch", + "pathe", + "react", + "react-dom", + "remark-parse", + "remeda", + "rolldown-plugin-dts", + "rollup", + "semver", + "serve-static", + "signal-exit", + "source-map", + "tinybench", + "tinyexec", + "tsx", + "typescript", + "unified", + "valibot", + "vue", + "web-tree-sitter", + "ws", + "zx" + ], + "enabled": false + }, + { + "description": "Ignore root workspace crates shared with rolldown/Cargo.toml and merged by .github/workflows/upgrade-deps.yml. Keep this list aligned with Rolldown's registry dependencies, using package names for renamed crates; project-only crates and other manifests remain enabled.", + "matchManagers": ["cargo"], + "matchFileNames": ["Cargo.toml"], + "matchPackageNames": [ + "anyhow", + "append-only-vec", + "arcstr", + "async-channel", + "async-scoped", + "base-encode", + "base64-simd", + "bitflags", + "blake3", + "cow-utils", + "criterion2", + "dashmap", + "derive_more", + "dunce", + "fast-glob", + "flate2", + "form_urlencoded", + "futures", + "glob", + "heck", + "idna_adapter", + "ignore", + "indexmap", + "infer", + "insta", + "itertools", + "itoa", + "json-escape-simd", + "json-strip-comments", + "jsonschema", + "memchr", + "mimalloc-safe", + "mime", + "napi", + "napi-build", + "napi-derive", + "nodejs-built-in-modules", + "nom", + "num-bigint", + "num_cpus", + "owo-colors", + "parking_lot", + "path-posix", + "percent-encoding", + "petgraph", + "phf", + "pnp", + "prettyplease", + "proc-macro2", + "quote", + "rayon", + "regex", + "regress", + "rolldown-ariadne", + "rolldown-notify", + "rolldown-notify-debouncer-full", + "rustc-hash", + "schemars", + "self_cell", + "serde", + "serde_json", + "serde_yaml", + "simdutf8", + "smallvec", + "sugar_path", + "supports-color", + "syn", + "terminal_size", + "testing_macros", + "tokio", + "tracing", + "tracing-chrome", + "tracing-subscriber", + "ts-rs", + "typedmap", + "url", + "uuid", + "vfs", + "walkdir", + "xxhash-rust" + ], + "enabled": false + }, { "description": "Ignore vite-task git dependency digest updates: every crate from that repository shares one revision and is bumped by hand with the bump-vite-task skill. Match the git source, not crate names, so crates added upstream (pty_terminal_test, snapshot_test, vt_select) stay covered without editing a list here.", "matchDatasources": ["git-refs"],