Skip to content

chore(ocm-kit): move tool pins from tools.lock to .env - #66

Merged
cbrgm merged 3 commits into
open-component-model:mainfrom
cbrgm:ocm-kit/tools-env
Oct 7, 2026
Merged

cbrgm merged 3 commits into
open-component-model:mainfrom
cbrgm:ocm-kit/tools-env

Conversation

@cbrgm

@cbrgm cbrgm commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

What this PR does / why we need it

Moves the ocm-kit tool pins from tools.lock to .env, same format as the monorepo.

  • ocm-kit/.env -> golangci-lint, osv-scanner and the OCM CLI, each with a # renovate: datasource=go depName=... comment
  • Makefile -> include .env, one small rule per tool instead of the generic tools.lock pattern rule. Binaries are versioned now (golangci-lint-v2.14.0, ocm-v0.15.0), so a bump in .env reinstalls by itself. No more hidden .version files and no cli -> ocm copy step
  • renovate.json -> the generic .env regex manager, copied 1:1 from the monorepo
  • ocm-kit.yaml -> CI reads the golangci-lint version from .env
  • leftover from chore(ocm-kit): remove nix dev shell #65: Makefile comment still mentioned the dev shell, separate commit

Why: step 2 of moving ocm-kit to the org tooling. The monorepo keeps its tool versions in .env with renovate comments and loads it via dotenv in the Taskfile. With the pins already there, the Makefile -> Taskfile switch (next PR) is just swapping the runner.

Renovate tracking doesnt change: the depNames are the same package paths Renovate resolves today, and the regex already bumps v-prefixed go datasource pins in the monorepo (e.g. DEEPCOPY_GEN_VERSION).

Testing:

$ make clean && make test golangci-lint scan
ok  	github.com/open-component-model/community/ocm-kit/compver	coverage: 96.4% of statements
ok  	github.com/open-component-model/community/ocm-kit/helmvalues	coverage: 83.1% of statements
Installing golangci-lint v2.14.0...
0 issues.
Installing osv-scanner v2.6.0...
Total 0 packages affected by 0 known vulnerabilities (0 Critical, 0 High, 0 Medium, 0 Low, 0 Unknown) from 1 ecosystem.

$ make golangci-lint   # second run, no reinstall
0 issues.

$ make e2e
✓ Test 6 passed: usable component-descriptor based OCI reference (...) was returned

$ grep '^GOLANGCI_LINT_VERSION=' .env | cut -d= -f2   # what CI reads
v2.14.0

$ renovate-config-validator ocm-kit/renovate.json
 INFO: Config validated successfully against 1 file(s)

Which issue(s) this PR fixes

Signed-off-by: Chris Bargmann <github@cbrgm.net>
@cbrgm
cbrgm force-pushed the ocm-kit/tools-env branch from 9abf03f to 19bb192 Compare October 2, 2026 15:54
@cbrgm cbrgm changed the title chore(ocm-kit): pin tool versions in .env instead of tools.lock chore(ocm-kit): move tool pins from tools.lock to .env Oct 2, 2026
@cbrgm
cbrgm deployed to renovate October 2, 2026 15:54 — with GitHub Actions Active
Signed-off-by: Chris Bargmann <github@cbrgm.net>
@github-actions github-actions Bot added size/s and removed size/m labels Oct 2, 2026
@cbrgm
cbrgm deployed to renovate October 2, 2026 15:54 — with GitHub Actions Active
@cbrgm
cbrgm deployed to renovate October 5, 2026 07:50 — with GitHub Actions Active
@cbrgm
cbrgm merged commit 5dcd6b2 into open-component-model:main Oct 7, 2026
8 checks passed

This branch was successfully deployed

1 active deployment
renovate — 240496bb Deployed Oct 5, 2026 by cbrgm via renovate #184
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants