name: renovate on: schedule: - cron: "@daily" push: branches: - main jobs: renovate: runs-on: ubuntu-latest # REMOVED: job-level container block to avoid the runner's strict auth loop steps: - name: Checkout repository uses: actions/checkout@v4 - name: Run Renovate # Uses the Docker container directly as a step action uses: docker://ghcr.io/renovatebot/renovate:37.20.2 env: RENOVATE_CONFIG_FILE: "/workspace/infra/renovate/config.js" LOG_LEVEL: "debug" RENOVATE_TOKEN: ${{ secrets.RENOVATE_TOKEN }}