ci(release): categorize Renovate deps in generated release notes - #557
Conversation
✅ Deploy Preview for devsydev canceled.
|
✅ Deploy Preview for images-devsy-sh canceled.
|
|
Warning Review limit reached
Next review available in: 48 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
📝 WalkthroughWalkthroughAdds ChangesRelease Changelog Configuration
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/release.yml:
- Around line 3-8: The release-note category definition is using an unsupported
authors field, which prevents bot-authored dependency PRs from matching the
category as intended. Update the release configuration entry for Dependency
Updates in the release workflow to remove authors from that category and rely on
the supported title/labels/exclude fields, using the existing category block as
the target for the fix.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: 241b1e7b-51d9-4316-96e8-3df58abfb5fc
📒 Files selected for processing (1)
.github/release.yml
| - title: Dependency Updates | ||
| labels: | ||
| - dependencies | ||
| authors: | ||
| - renovate[bot] | ||
| - dependabot[bot] |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
# Check if there are any existing release.yml files in the repo or related docs
fd -i 'release\.yml' .github/
fd -i 'release' .github/Repository: devsy-org/devsy
Length of output: 253
🏁 Script executed:
#!/bin/bash
set -euo pipefail
printf '\n== .github/release.yml ==\n'
cat -n .github/release.yml
printf '\n== .github/workflows/release.yml ==\n'
cat -n .github/workflows/release.yml
printf '\n== Search for release notes docs or config references ==\n'
rg -n "authors|labels:|release notes|generate-notes|release.yml" .github README* docs* . 2>/dev/null | head -n 200Repository: devsy-org/devsy
Length of output: 18997
🌐 Web query:
GitHub auto-generated release notes .github/release.yml authors field categories labels authors docs
💡 Result:
For GitHub's built-in auto-generated release notes, configuration is performed by creating a.github/release.yml file in your repository [1][2]. This configuration allows you to exclude specific pull requests and organize them into categorized groups based on labels [1][3]. Configuration Options for.github/release.yml: Exclusions: You can exclude pull requests from the overall release notes or from specific categories by using the following keys: - changelog.exclude.labels: A list of labels that prevent a pull request from appearing in the release notes [1][4]. - changelog.exclude.authors: A list of GitHub user or bot login handles (e.g., 'dependabot') whose pull requests should be excluded [1][5]. - changelog.categories[].exclude.labels: Labels that exclude a pull request specifically from a certain category [1][2]. - changelog.categories[].exclude.authors: User or bot login handles that exclude a pull request specifically from a certain category [1][3]. Categorization: You can group pull requests using the changelog.categories key [1][4]: - title (Required): The heading for the category in the release notes [1][2]. - labels (Required): A list of labels that qualify a pull request for inclusion in the category [1][3]. You can use '' as a catch-all to include pull requests that did not match any other defined categories [1][4]. Example Configuration: #.github/release.yml changelog: exclude: authors: - dependabot categories: - title: Bugfixes labels: - bug - title: Features labels: - enhancement - title: Other Changes labels: - "" Note that while third-party tools like 'Release Drafter' also use a configuration file (typically.github/release-drafter.yml) to manage release notes, they operate independently of GitHub's native automatically generated release notes feature [6][7][8]. The native feature is strictly configured via.github/release.yml [1][3].
Citations:
- 1: https://docs.github.com/en/repositories/releasing-projects-on-github/automatically-generated-release-notes
- 2: https://docs.github.com/en/enterprise-cloud@latest/repositories/releasing-projects-on-github/automatically-generated-release-notes
- 3: https://docs.github.com/en/enterprise-server@3.13/repositories/releasing-projects-on-github/automatically-generated-release-notes
- 4: https://docs.github.com/en/enterprise-server@3.10/repositories/releasing-projects-on-github/automatically-generated-release-notes
- 5: https://yossarian.net/til/post/configuring-github-releases-with-release-yml/
- 6: https://github.com/release-drafter/release-drafter/blob/master/README.md
- 7: https://github.com/release-drafter/release-drafter
- 8: https://github.com/release-drafter/release-drafter/blob/master/action.yml
🌐 Web query:
site:docs.github.com auto-generated release notes authors labels categories release.yml
💡 Result:
GitHub supports automatically generated release notes, which can be customized by creating a configuration file at.github/release.yml (or.github/release.yaml) in your repository [1][2]. This file allows you to exclude specific pull request authors and labels from the generated notes, as well as define custom categories for your changes [1]. Configuration Options The configuration uses a YAML structure under the changelog key [1]. Global Exclusions You can define global exclusions to prevent certain pull requests from appearing in the release notes entirely [1]: - changelog.exclude.labels: A list of labels to exclude. - changelog.exclude.authors: A list of user or bot login handles to exclude. Categories You can organize pull requests into specific categories based on their labels [1]: - changelog.categories[].title: The title for the category [1]. - changelog.categories[].labels: The list of labels that qualify a pull request for this category [1]. You can use '' as a catch-all to include pull requests that did not match any previous categories [1]. - changelog.categories[].exclude.labels: Specific labels to exclude from this category [1]. - changelog.categories[].exclude.authors: Specific authors to exclude from this category [1]. Example Configuration Below is an example of how to categorize features and dependencies separately [1]: #.github/release.yml changelog: categories: - title: 🏕 Features labels: - '' exclude: labels: - dependencies - title: 👒 Dependencies labels: - dependencies If no configuration file is found, GitHub uses a default configuration for generating the notes [2][3]. Additionally, if you are generating release notes via the GitHub REST API, you can specify a custom path to a configuration file using the configuration_file_path parameter [2][3].
Citations:
- 1: https://docs.github.com/en/repositories/releasing-projects-on-github/automatically-generated-release-notes
- 2: https://docs.github.com/en/rest/releases/releases?apiVersion=2026-03-10&apiversion=2022-11-28%2F1000
- 3: https://docs.github.com/rest/releases/releases
🏁 Script executed:
#!/bin/bash
set -euo pipefail
printf '\n== Dependency-related config files ==\n'
git ls-files | rg '(^|/)(renovate\.json|renovate\.json5|renovate\.config\.js|dependabot\.yml|dependabot\.yaml|release\.yml|release\.yaml|actionlint\.yaml|package\.json|go\.mod)$' || true
printf '\n== Search for dependencies label / renovate / dependabot ==\n'
rg -n --hidden --glob '!.git' --glob '!node_modules' --glob '!dist' --glob '!build' \
'dependencies|renovate|dependabot|label' \
.github . 2>/dev/null | head -n 250Repository: devsy-org/devsy
Length of output: 19543
🏁 Script executed:
#!/bin/bash
set -euo pipefail
printf '\n== renovate.json ==\n'
cat -n renovate.json
printf '\n== Dependabot config ==\n'
if [ -f .github/dependabot.yml ]; then cat -n .github/dependabot.yml; fi
if [ -f .github/dependabot.yaml ]; then cat -n .github/dependabot.yaml; fi
printf '\n== Search for a dependencies label rule in GitHub config ==\n'
rg -n --hidden --glob '!.git' 'dependencies' .github renovate.json . 2>/dev/null | head -n 120Repository: devsy-org/devsy
Length of output: 11619
Drop authors from the release notes category
GitHub release-note categories support title, labels, and exclude; authors is only valid under exclude. As written, this still requires the dependencies label, so bot-authored dependency PRs without that label will end up in “Other Changes”.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/release.yml around lines 3 - 8, The release-note category definition
is using an unsupported authors field, which prevents bot-authored dependency
PRs from matching the category as intended. Update the release configuration
entry for Dependency Updates in the release workflow to remove authors from that
category and rely on the supported title/labels/exclude fields, using the
existing category block as the target for the fix.
Adds
.github/release.ymlto control GitHub's auto-generated release notes.Renovate (and Dependabot) PRs are now grouped under a dedicated Dependency Updates category instead of mixing into the main changelog. All other PRs fall under Other Changes. Author-based matching is used since the Renovate config does not apply labels.
Summary by CodeRabbit