Skip to content

ci: Narrowed the Dependabot updates to safe minor and patch versions - #53

Merged
Axeloooo merged 2 commits into
develfrom
ci/dependabot-rules
Oct 9, 2026
Merged

Axeloooo merged 2 commits into
develfrom
ci/dependabot-rules

Conversation

@Axeloooo

@Axeloooo Axeloooo commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

Issue

The first Dependabot run (config from #34) opened 14 pull requests, many of them majors that need deliberate migration work (ESLint 10, TypeScript 7, Stripe.js 10, Aspire 13) or that touch the course-pinned test tooling. The owner's decision after triage: take only safe minor and patch updates automatically, ignore majors that need deliberate work, and only use releases that are at least 14 days old.

Solution

.github/dependabot.yml (still version 2, target-branch: devel, weekly, unscoped ci/chore prefixes, open-pull-requests-limit: 5):

  • github-actions: one group actions with patterns: ["*"], so every actions update (majors included) arrives as a single pull request. cooldown.default-days: 14 (GitHub Actions does not support the per-semver cooldown keys).
  • npm (/frontend): keeps the npm-minor-and-patch group; adds ignore rules for the majors below; cooldown with default-days: 14 and semver-major-days: 30.
  • nuget (/backend): keeps the nuget-minor-and-patch group; ignores every major, Aspire minors and the pinned packages below; cooldown with default-days: 14 and semver-major-days: 30.

Every ignore rule lists update-types (none ignores a package by name only), so no rule would block a security fix.

Security coverage (second commit). Dependabot alerts and security updates are repository settings and are currently off; the owner enables them under Settings > Code security (not changed here). Security updates always target the default branch (devel), and with target-branch set GitHub does not apply this file's options to them. As a compensating control, ci.yml gets a new job Dependency audit (contents: read, no secrets, runs on pull requests, pushes and through workflow_call from release.yml):

  • npm ci --ignore-scripts then npm audit --omit=dev --audit-level=high in frontend/ (gating: production dependencies);
  • npm audit --audit-level=high for all dependencies, a ::warning only (dev tooling; it currently reports 11 high findings in dev tools);
  • dotnet restore and dotnet list backend/Backend.sln package --include-transitive --vulnerable, failing when the output contains has the following vulnerable packages (the command exits 0 either way).

The CI diagram in docs/architecture.md shows the fifth job. The "Pull container images" step comment now says to recheck the list on every Testcontainers bump.

Each rule has a YAML comment with its reason. Docs updated: the Dependabot subsection of docs/architecture.md, the README Dependabot line and the glossary Dependabot row. No Mermaid diagram changed; CLAUDE.md has no line that became false.

Ignore rules

Ecosystem Dependency Ignored update types Reason
npm eslint major ESLint 10 changes the flat config and rules; one manual migration with @eslint/js
npm @eslint/js major Moves with eslint
npm eslint-plugin-react-hooks major 7 adds the React Compiler lint rules; part of the ESLint migration
npm typescript major TypeScript 7 is the native compiler; tsc -b and typescript-eslint need checking
npm @stripe/stripe-js major Stripe.js API changes in the checkout flow
npm @stripe/react-stripe-js major 7 requires @stripe/stripe-js 10 (peer range), so both move together by hand
npm vite major Vite 8 is outside @vitejs/plugin-react 4.7's peer range (^4.2 || ^5 || ^6 || ^7), so npm ci would fail
npm @vitejs/plugin-react major 6 requires Vite 8 (peerDependencies.vite: ^8.0.0)
npm @types/react, @types/react-dom major Follow the React major (18)
npm @types/node major Follows the Node major used in CI (22)
nuget * major Backend targets .NET 8 and Aspire 9.5; majors (EF Core 10, Aspire 13, ...) need a framework upgrade
nuget Aspire.* major, minor Stay on 9.5.x patches to match the Aspire 9.5.2 hosting
nuget xunit, xunit.runner.visualstudio, FluentAssertions, Moq, NSubstitute major, minor Course-pinned test tooling in the unit test project (CLAUDE.md); patches stay allowed so fixes can arrive
nuget Testcontainers.* major, minor Newer versions change default image tags; even a patch can, so check the CI "Pull container images" list on each Testcontainers PR; lift once that list is reviewed

Not ignored on purpose: react/react-dom 19 (arrives as its own major PR), globals 17, and Microsoft.NET.Test.Sdk (minor/patch allowed, majors covered by the * rule).

Note: ignore rules are per package name across the /backend directory, so the xunit.runner.visualstudio and NSubstitute rules also hold those packages in the integration test project.

Dependabot PRs expected to close after this lands

Dependabot only re-evaluates after the config reaches the default branch, so this is expected, not yet observed:

Test cases

  • Dependency audit gate, tested locally: on this tree dotnet list ... --vulnerable reports no vulnerable packages and the grep gate passes; in a scratch copy of backend/ with System.Text.RegularExpressions pinned to 4.3.0 the command still exits 0 but prints Project GameStore.Api.UnitTests has the following vulnerable packages (High, GHSA-cmhx-cq75-c4mj) and the gate fails. npm audit --omit=dev --audit-level=high: 0 vulnerabilities (exit 0).

  • commitlint 21.2.3 with .commitlintrc.json on both commits: 0 problems. CI diagram validated as Mermaid.

  • yamllint -d '{extends: relaxed, rules: {new-lines: disable, line-length: disable}}' .github/dependabot.yml: clean.

  • Converted the YAML to JSON and validated it against the SchemaStore Dependabot schema (https://json.schemastore.org/dependabot-2.0.json, draft-07) with ajv-cli@5.0.0: valid. A negative check with an unknown cooldown key was reported invalid, so the schema does check the cooldown block.

  • Cooldown keys checked against the GitHub Dependabot options reference: default-days and semver-major-days exist; npm and NuGet support the semver keys, GitHub Actions only default-days.

  • Peer ranges checked with npm view (@vitejs/plugin-react, @stripe/react-stripe-js); majors listed from npm outdated in frontend/.

  • CI on this pull request.

Follow-up

  • @stripe/stripe-js 8.x is no longer released (latest is 10.0.0), so the Stripe 10 upgrade together with @stripe/react-stripe-js 7 should be a deliberate follow-up pull request.

UI changes

None.

@Axeloooo Axeloooo self-assigned this Oct 9, 2026
@Axeloooo

Axeloooo commented Oct 9, 2026

Copy link
Copy Markdown
Owner Author

@Axeloooo this PR is ready for your review

@Axeloooo
Axeloooo merged commit 007e2c3 into devel Oct 9, 2026
6 checks passed
@Axeloooo
Axeloooo deleted the ci/dependabot-rules branch October 9, 2026 23:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant