main
renovate-bot
Central Renovate configuration for all repos on scm.cabillot.eu.
How it works
This repo (public) contains:
config.json— global Renovate config (no secrets, only placeholders resolved at runtime).gitea/workflows/renovate.yaml— reusable Gitea Actions workflow (workflow_call)
Being public allows the Gitea Actions runner to clone this repo for reusable workflow calls. No secrets are stored here — they come from org-level secrets on the calling repo's org.
Adopting Renovate in a repo
Add this workflow file to your repo at .gitea/workflows/renovate.yaml:
name: Renovate
on:
schedule:
- cron: '0 0 */2 * *'
push:
branches:
- main
workflow_dispatch:
jobs:
renovate:
uses: perso/renovate-bot/.gitea/workflows/renovate.yaml@main
secrets: inherit
That's it. Renovate will:
- Scan every 2 days for dependency updates
- Re-run on every push to
main(after merges) to rebase stale PRs - Be triggerable manually via
workflow_dispatch(UI or API)
Per-repo overrides
Add a renovate.json at the root of your repo. It will be merged with the
global config.
Required secrets
These must be set as org-level secrets in the Gitea org of the consumer repo:
| Secret | Purpose |
|---|---|
RENOVATE_TOKEN |
Gitea API token for the renovate bot |
RENOVATE_GITHUB_TOKEN |
GitHub token for GitHub-hosted dependencies |
RENOVATE_SSH_KEY |
SSH private key for git operations (optional) |
Description
Central Renovate configuration — reusable Gitea Actions workflow + global config
28 KiB