Skip to content

feat: add customUpdateCommands to allow overwrite update logic - #42054

Draft
secustor wants to merge 8 commits into
renovatebot:mainfrom
secustor:feat/add-updateCommands
Draft

secustor wants to merge 8 commits into
renovatebot:mainfrom
secustor:feat/add-updateCommands

Conversation

@secustor

@secustor secustor commented Mar 22, 2026 •

Copy link
Copy Markdown
Member

Changes

This is a draft for a new customUpdateCommands configuration. Which if applied overwrites the replacement logic.

This iteration also supports lockfileMaintenance

Context

This is useful in combination with CustomManager, if the a simply replacing is not enough as external tooling could use the packageFile as state ( which version is currently applied )

Please select one of the following:

  • This closes an existing Issue, Closes: #
  • This doesn't close an Issue, but I accept the risk that this PR may be closed if maintainers disagree with its opening or implementation

AI assistance disclosure

Did you use AI tools to create any part of this pull request?

Please select one option and, if yes, briefly describe how AI was used (e.g., code, tests, docs) and which tool(s) you used.

  • No — I did not use AI for this contribution.
  • Yes — minimal assistance (e.g., IDE autocomplete, small code completions, grammar fixes).
  • Yes — substantive assistance (AI-generated non‑trivial portions of code, tests, or documentation).
  • Yes — other (please describe):

Documentation (please check one with an [x])

  • I have updated the documentation, or
  • No documentation update is required

How I've tested my work (please select one)

I have verified these changes via:

  • Code inspection only, or
  • Newly added/modified unit tests, or
  • No unit tests, but ran on a real repository, or
  • Both unit tests + ran on a real repository

The public repository:

TODOs:

  • can we unify this with postUpgradeTasks?
  • or at least reuse some parts?

@jamietanna
jamietanna self-requested a review March 23, 2026 10:16
@jamietanna jamietanna self-assigned this Mar 26, 2026
Comment thread docs/usage/configuration-options.md Outdated
Comment thread lib/config/options/index.ts
Comment thread docs/usage/configuration-options.md Outdated
Comment thread docs/usage/configuration-options.md
All file changes produced by the commands (additions, modifications, and deletions) are captured via `git status` and committed by Renovate.
This makes `customUpdateCommands` well-suited for tools like the [Backstage CLI](https://backstage.io/docs/tooling/cli/commands/#versionsbump), which updates `backstage.json`, `package.json`, `yarn.lock`, and other files in a single invocation.

Each command must match at least one of the patterns defined in [`allowedCommands`](./self-hosted-configuration.md#allowedcommands) (a global-only configuration option) in order to be executed.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Might be worth keeping a similar note to what we have re Post-upgrade tasks are blocked by default for security reasons ...?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We haven't such a note in postUpgradeTasks, but we can add such one to allowedCommands

Comment thread docs/usage/configuration-options.md
Comment thread lib/config/migrations/migrations-service.ts Outdated
Comment thread lib/workers/repository/update/branch/execute-update-commands.ts
try {
logger.trace({ cmd: compiledCmd }, 'Executing update command');

const execOpts: ExecOptions = {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we keep the same warning as we have in lib/workers/repository/update/branch/execute-post-upgrade-commands.ts?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do you mean?

// WARNING to self-hosted administrators: always run post-upgrade commands with `shell` mode on, which has the risk of arbitrary environment variable access or additional command execution
// It is very likely this will be susceptible to these risks, even if you allowlist (via `allowedCommands`), as there may be special characters included in the given commands that can be leveraged here

That should be rather added to the documentation rather code.

@jamietanna jamietanna left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Few comments, but happy with the overall design and approach - especially as it's very close code wise to how we're doing postUpgradeTasks (which I know is intentional)

@jamietanna

Copy link
Copy Markdown
Contributor

IMO, let's keep the duplication in place between them - I prefer the "rule of 3" rather than "don't repeat yourself" - there are a few things that are different between them, and we won't know until - maybe - we add a third thing like this where the duplication is and what's special to each case

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants