Skip to content

Renovate config groups security PRs with stalled dependency PRs, leaving CVEs unpatched #3484

Description

@fullsend-ai-retro

What happened

Renovate created standalone security PRs (#3473, #3474, #3475) to bump go-git/go-git/v5 from v5.19.1 to v5.19.2, fixing CVE-2026-71556 (CVSS 7.1 High, symlink traversal) and CVE-2026-71557 (CVSS 6.3 Medium, path traversal). All three PRs were autoclosed by Renovate on Aug 8, 2026 because Renovate considered them redundant to existing grouped "Update go modules" PRs (e.g., #3130 for main). However, none of the grouped PRs actually include the go-git v5.19.2 bump — PR #3130 has been open since Feb 27, 2026 (5+ months) and only updates go-billy, not go-git. As of Aug 8, all three branches (main, release-v0.7, release-v0.8) still run go-git v5.19.1 with both CVEs unpatched. This is a recurring pattern: the same autoclosure happened with go-git v5.19.1 in June 2026 (PRs #3250, #3252, #3253 autoclosed; a manual PR #3335 was eventually needed).

What could go better

The shared Renovate config at conforma/.github/config/renovate/renovate.json groups all Go module updates under groupName: "go modules" with no exception for vulnerability alerts. When Renovate creates a standalone security PR and then detects the same package tracked in an existing grouped PR, it autoclosures the security PR as redundant — even if the grouped PR is months stale and does not actually contain the security update. The grouped PRs become stalled because they bundle many changes into XXL-sized PRs that are harder to review and merge. This creates a deadlock: security PRs are autoclosed as redundant, while the grouped PR that supposedly covers them never merges. Confidence is high — this is the second time this exact pattern has occurred for go-git in this repo, and the mechanism is clearly documented in Renovate's behavior and the config.

Proposed change

Add a vulnerabilityAlerts override to the Renovate config (either in conforma/cli/renovate.json or in the shared config at conforma/.github/config/renovate/renovate.json) that prevents security/vulnerability PRs from being grouped:

{
  "vulnerabilityAlerts": {
    "groupName": null,
    "labels": ["security"],
    "schedule": ["at any time"]
  }
}

This ensures vulnerability alert PRs are created and maintained as standalone PRs, not autoclosed as redundant to grouped PRs. The groupName: null overrides the go modules grouping. The schedule: ["at any time"] ensures security PRs are not delayed by the daily schedule. Additionally, as an immediate action, the go-git v5.19.2 update should be applied manually (or by re-opening/recreating the security PRs) to patch the two outstanding CVEs on all active branches.

Validation criteria

  1. The next Renovate vulnerability alert PR for a Go module in conforma/cli should be created as a standalone PR (not grouped into "Update go modules") and should NOT be autoclosed. 2. The go-git v5.19.2 security update should be merged on main, release-v0.7, and release-v0.8 within 1 week. 3. Over the next 3 months, no standalone Go module security PRs should be autoclosed as redundant to stalled grouped PRs.

Generated by retro agent from #3475

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    duplicateThis issue or pull request already existsready-for-triageTriggers triage agent dispatch

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions