Skip to content

renovate: vulnerability-alert fix PRs - #7

Merged
apostasie merged 1 commit into
mainfrom
claudio/renovate-vulnerability-alerts
Sep 6, 2026
Merged

renovate: vulnerability-alert fix PRs#7
apostasie merged 1 commit into
mainfrom
claudio/renovate-vulnerability-alerts

Conversation

@closer-claudio

Copy link
Copy Markdown
Contributor

Stated explicitly rather than left to the preset default, because vulnerabilityAlerts.enabled: true is what reaches // indirect Go modules: the gomod manager disables indirect deps, and the alert path re-enables one only when this object says enabled. Fix PRs skip the release-age cooldown (a known-vulnerable version is the worse risk) and take the lowest fixed version — both Renovate defaults. Same change as in limen's canonical renovate.json5.

🤖 Generated with Claude Code

Stated explicitly rather than left to the preset default, because
`vulnerabilityAlerts.enabled: true` is what reaches `// indirect` Go
modules: the gomod manager disables indirect deps, and the alert path
re-enables one only when this object says enabled. Fix PRs skip the
release-age cooldown (a known-vulnerable version is the worse risk) and
take the lowest fixed version — both Renovate defaults for this object.
Same change as landed in limen's canonical renovate.json5.

Signed-off-by: closer-claudio <claudio@farcloser.world>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@apostasie
apostasie merged commit e5319a6 into main Sep 6, 2026
4 checks passed
@apostasie
apostasie deleted the claudio/renovate-vulnerability-alerts branch September 6, 2026 23:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants