Repository navigation
ci: Narrowed the Dependabot updates to safe minor and patch versions - #53
Merged
Merged
Conversation
Owner
Author
|
@Axeloooo this PR is ready for your review |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Issue
The first Dependabot run (config from #34) opened 14 pull requests, many of them majors that need deliberate migration work (ESLint 10, TypeScript 7, Stripe.js 10, Aspire 13) or that touch the course-pinned test tooling. The owner's decision after triage: take only safe minor and patch updates automatically, ignore majors that need deliberate work, and only use releases that are at least 14 days old.
Solution
.github/dependabot.yml(still version 2,target-branch: devel, weekly, unscopedci/choreprefixes,open-pull-requests-limit: 5):actionswithpatterns: ["*"], so every actions update (majors included) arrives as a single pull request.cooldown.default-days: 14(GitHub Actions does not support the per-semver cooldown keys)./frontend): keeps thenpm-minor-and-patchgroup; addsignorerules for the majors below;cooldownwithdefault-days: 14andsemver-major-days: 30./backend): keeps thenuget-minor-and-patchgroup; ignores every major, Aspire minors and the pinned packages below;cooldownwithdefault-days: 14andsemver-major-days: 30.Every ignore rule lists
update-types(none ignores a package by name only), so no rule would block a security fix.Security coverage (second commit). Dependabot alerts and security updates are repository settings and are currently off; the owner enables them under Settings > Code security (not changed here). Security updates always target the default branch (
devel), and withtarget-branchset GitHub does not apply this file's options to them. As a compensating control,ci.ymlgets a new job Dependency audit (contents: read, no secrets, runs on pull requests, pushes and throughworkflow_callfromrelease.yml):npm ci --ignore-scriptsthennpm audit --omit=dev --audit-level=highinfrontend/(gating: production dependencies);npm audit --audit-level=highfor all dependencies, a::warningonly (dev tooling; it currently reports 11 high findings in dev tools);dotnet restoreanddotnet list backend/Backend.sln package --include-transitive --vulnerable, failing when the output containshas the following vulnerable packages(the command exits 0 either way).The CI diagram in
docs/architecture.mdshows the fifth job. The "Pull container images" step comment now says to recheck the list on every Testcontainers bump.Each rule has a YAML comment with its reason. Docs updated: the Dependabot subsection of
docs/architecture.md, the README Dependabot line and the glossary Dependabot row. No Mermaid diagram changed; CLAUDE.md has no line that became false.Ignore rules
eslint@eslint/js@eslint/jseslinteslint-plugin-react-hookstypescripttsc -band typescript-eslint need checking@stripe/stripe-js@stripe/react-stripe-js@stripe/stripe-js10 (peer range), so both move together by handvite@vitejs/plugin-react4.7's peer range (^4.2 || ^5 || ^6 || ^7), sonpm ciwould fail@vitejs/plugin-reactpeerDependencies.vite: ^8.0.0)@types/react,@types/react-dom@types/node*Aspire.*xunit,xunit.runner.visualstudio,FluentAssertions,Moq,NSubstituteTestcontainers.*Not ignored on purpose:
react/react-dom19 (arrives as its own major PR),globals17, andMicrosoft.NET.Test.Sdk(minor/patch allowed, majors covered by the*rule).Note: ignore rules are per package name across the
/backenddirectory, so thexunit.runner.visualstudioandNSubstituterules also hold those packages in the integration test project.Dependabot PRs expected to close after this lands
Dependabot only re-evaluates after the config reaches the default branch, so this is expected, not yet observed:
@eslint/js9 -> 10 (ignored major)typescript5.9 -> 7.0 (ignored major)eslint9 -> 10 (ignored major)@stripe/stripe-js8 -> 10 (ignored major)Aspire.Azure.*9.5.2 -> 13.6.1 (ignored major)Test cases
Dependency audit gate, tested locally: on this tree
dotnet list ... --vulnerablereports no vulnerable packages and the grep gate passes; in a scratch copy ofbackend/withSystem.Text.RegularExpressionspinned to 4.3.0 the command still exits 0 but printsProject GameStore.Api.UnitTests has the following vulnerable packages(High, GHSA-cmhx-cq75-c4mj) and the gate fails.npm audit --omit=dev --audit-level=high: 0 vulnerabilities (exit 0).commitlint 21.2.3 with
.commitlintrc.jsonon both commits: 0 problems. CI diagram validated as Mermaid.yamllint -d '{extends: relaxed, rules: {new-lines: disable, line-length: disable}}' .github/dependabot.yml: clean.Converted the YAML to JSON and validated it against the SchemaStore Dependabot schema (
https://json.schemastore.org/dependabot-2.0.json, draft-07) withajv-cli@5.0.0:valid. A negative check with an unknowncooldownkey was reportedinvalid, so the schema does check thecooldownblock.Cooldown keys checked against the GitHub Dependabot options reference:
default-daysandsemver-major-daysexist; npm and NuGet support the semver keys, GitHub Actions onlydefault-days.Peer ranges checked with
npm view(@vitejs/plugin-react,@stripe/react-stripe-js); majors listed fromnpm outdatedinfrontend/.CI on this pull request.
Follow-up
@stripe/stripe-js8.x is no longer released (latest is 10.0.0), so the Stripe 10 upgrade together with@stripe/react-stripe-js7 should be a deliberate follow-up pull request.UI changes
None.