Files
frontend/renovate.json
T
Franck NijhofandClaude 2679d83028 Migrate from Yarn to pnpm (#54392)
* Migrate from Yarn to pnpm

Switch the package manager to pnpm 11, keeping every resolved
dependency version from yarn.lock.

- Move resolutions to pnpm overrides and Yarn patches to patches/
- Enable supply-chain protection: 3 day minimum release age,
  trust policy that blocks provenance downgrades, and dependency
  build scripts denied by default
- Declare dependencies that were imported but only available through
  Yarn's hoisting: zrender, @lezer/common, zxing-wasm,
  @babel/helper-compilation-targets, core-js-compat, @types/geojson
- Look up pinned license overrides in pnpm's node_modules layout
- Update CI, scripts, git hooks, Renovate, and documentation

* Cache the pnpm store with node_modules in CI

Jobs that restore the shared node_modules cache skip the install, so
the pnpm store is empty there. The license file generation runs
`pnpm licenses list`, which reads package metadata from the store and
fails without it.

* Point the demo e2e comment at the real test:e2e:demo script

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-30 11:32:16 +00:00

150 lines
5.5 KiB
JSON

{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"configMigration": true,
"extends": [
":ignoreModulesAndTests",
":label(Dependencies)",
":pinVersions",
":prConcurrentLimit10",
":semanticCommitsDisabled",
"group:monorepos",
"group:recommended"
],
"enabledManagers": ["npm", "nvm", "custom.regex", "github-actions"],
"minimumReleaseAge": "3 days",
"postUpdateOptions": ["pnpmDedupe"],
"lockFileMaintenance": {
"description": ["Run after patch releases but before next beta"],
"enabled": true,
"schedule": ["on the 19th day of the month before 4am"]
},
"customDatasources": {
"ha-core-python": {
"defaultRegistryUrlTemplate": "https://raw.githubusercontent.com/home-assistant/core/dev/.python-version",
"format": "plain"
}
},
"customManagers": [
{
"description": "Keep PYTHON_VERSION in sync with home-assistant/core (patch + minor)",
"customType": "regex",
"managerFilePatterns": ["/^\\.github/workflows/[^/]+\\.ya?ml$/"],
"matchStrings": ["PYTHON_VERSION: \"(?<currentValue>[^\"]+)\""],
"depNameTemplate": "python",
"datasourceTemplate": "custom.ha-core-python",
"versioningTemplate": "python"
},
{
"description": "Keep devcontainer image and requires-python in sync with home-assistant/core (minor only)",
"customType": "regex",
"managerFilePatterns": [
"/^\\.devcontainer/Dockerfile$/",
"/^pyproject\\.toml$/"
],
"matchStrings": [
"devcontainers/python:(?<currentValue>[\\d.]+)",
"requires-python = \">=(?<currentValue>[^\"]+)\""
],
"depNameTemplate": "python",
"datasourceTemplate": "custom.ha-core-python",
"versioningTemplate": "python",
"extractVersionTemplate": "^(?<version>\\d+\\.\\d+)"
},
{
"description": "Keep actionlint used in CI up to date",
"customType": "regex",
"managerFilePatterns": ["/^\\.github/workflows/actionlint\\.yaml$/"],
"matchStrings": ["ACTIONLINT_VERSION: (?<currentValue>\\S+)"],
"depNameTemplate": "rhysd/actionlint",
"datasourceTemplate": "github-releases",
"extractVersionTemplate": "^v(?<version>.+)$"
},
{
"description": "Keep Playwright CI container image up to date",
"customType": "regex",
"managerFilePatterns": ["/^\\.github/workflows/e2e\\.yaml$/"],
"matchStrings": [
"mcr\\.microsoft\\.com/playwright:(?<currentValue>v\\d+\\.\\d+\\.\\d+-noble)"
],
"depNameTemplate": "mcr.microsoft.com/playwright",
"datasourceTemplate": "docker",
"versioningTemplate": "regex:^v(?<major>\\d+)\\.(?<minor>\\d+)\\.(?<patch>\\d+)-(?<compatibility>noble)$"
}
],
"packageRules": [
{
"description": "Group all Python version updates from home-assistant/core",
"matchDepNames": ["python"],
"matchDatasources": ["custom.ha-core-python"],
"groupName": "Python version"
},
{
"description": "MDC packages are pinned to the same version as MWC",
"extends": ["monorepo:material-components-web"],
"enabled": false
},
{
"description": "Group MDI packages",
"groupName": "Material Design Icons",
"matchPackageNames": ["@mdi/js", "@mdi/svg"]
},
{
"description": "Group tsparticles engine and presets",
"groupName": "tsparticles",
"matchPackageNames": ["@tsparticles/engine", "@tsparticles/preset-{/,}**"]
},
{
"description": "Group date-fns with dependent timezone package",
"groupName": "date-fns",
"matchPackageNames": ["date-fns", "date-fns-tz"]
},
{
"description": "Group formatjs monorepo package",
"groupName": "formatjs",
"matchPackageNames": ["@formatjs/**"]
},
{
"description": "Group Playwright package and CI container updates",
"groupName": "Playwright",
"matchPackageNames": ["@playwright/test", "mcr.microsoft.com/playwright"],
"minimumGroupSize": 5
},
{
"description": "MCR returns no release timestamps, so the minimum release age would keep the Playwright container pending forever. The npm package still gates the group.",
"matchPackageNames": ["mcr.microsoft.com/playwright"],
"minimumReleaseAge": null
},
{
"description": "GitHub Actions: weekly, with a 7 day cooldown, like Dependabot did",
"matchManagers": ["github-actions"],
"addLabels": ["GitHub Actions"],
"schedule": ["before 8am on monday"],
"minimumReleaseAge": "7 days"
},
{
"description": "Leave runner labels and action version inputs alone, Dependabot never updated those",
"matchManagers": ["github-actions"],
"matchDepTypes": ["github-runner", "uses-with"],
"enabled": false
},
{
"description": "The Playwright container is already managed by the custom regex manager. Extracting it twice would break the minimumGroupSize count of the Playwright group.",
"matchManagers": ["github-actions"],
"matchPackageNames": ["mcr.microsoft.com/playwright"],
"enabled": false
},
{
"description": "Group the github/codeql-action subactions into one PR (they share a release)",
"matchPackageNames": ["/^github\\/codeql-action(?:\\/|$)/"],
"groupName": "github/codeql-action",
"groupSlug": "codeql-action"
},
{
"description": "Group the actions/cache subactions into one PR (they share a release)",
"matchPackageNames": ["/^actions\\/cache(?:\\/|$)/"],
"groupName": "actions/cache",
"groupSlug": "actions-cache"
}
]
}