chore: have renovate rebase stale PRs before merging (#4782)
Set rebaseWhen=behind-base-branch in the package.json renovate block so any renovate PR whose base has moved gets re-pushed and re-tested against the new tip before it can land. This closes a class of merge-time race we just hit: PR #4781 (tinyexec 1.1.2 -> 1.2.2) passed CI on a base that pinned pnpm@11.1.2, but was squash-merged on top of master after PR #4776 had bumped pnpm to 11.3.0. pnpm 11.3.0 added a supply-chain verification pass that re-applies the default minimumReleaseAge (1440 min) to every lockfile entry on every install -- 11.1.2 only checked it at resolve time, so the renovate PR's --frozen-lockfile run never noticed tinyexec@1.2.2 was too new. Post-merge, master CI failed with ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION until the package aged in. Forcing a rebase before merge surfaces that mismatch in the PR run, where it can be retried or held, instead of breaking master. Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
E
escapedcat committed
2960a0cec39fbfea6588c6e25441763dabd714ec
Parent: 74ed978
Committed by GitHub <noreply@github.com>
on 5/24/2026, 4:23:27 PM