Skip to content

Replace secrets-analyzer-deps-bot with renovate

Proposal

Following the work in #557439 to replace the SAST analyzer dependency bot with Renovate, the Secret Detection team should perform the same migration for the secrets analyzer.

Implementation Plan

  1. Generate forks for Secret Detection projects by adding to forks/config.tfvars based on this doc
    • Secrets analyzer project(s)
  2. Ensure changelog-parser script is available for updating changelog entries
  3. Add new template to ci-templates repo to update changelog with correct MR IID (if not already completed in #557439)
  4. Update bot script to download and run changelog-parser
  5. Create Config for Secret Detection projects based on this doc
    • Secrets analyzer project(s)
  6. Remove the relevant pipeline schedules from the secrets-analyzer-deps-bot that generates the dependency update MRs
    • Secrets analyzer project(s)

Related to #557439

Edited by 🤖 GitLab Bot 🤖