Skip to content

docs(deps): document the Dependabot release-age lockfile fix - #801

Open
EricAndrechek wants to merge 1 commit into
mainfrom
deps/dependabot-cooldown
Open

EricAndrechek wants to merge 1 commit into
mainfrom
deps/dependabot-cooldown

Conversation

@EricAndrechek

Copy link
Copy Markdown
Member

Summary

The code half of #441 has already landed: .github/dependabot.yml carries a 7-day cooldown (with the same @wave-rf/* and @wavehouse/* excludes as minimumReleaseAgeExclude), and pnpm 11.21 now verifies the lockfile against minimumReleaseAge even under --frozen-lockfile, so the "CI does not catch this" premise in the issue is stale. What is left is transitive packages that Dependabot's age-blind resolver pulls in, which a cooldown cannot prevent (it gates only the package being bumped).

This PR adds no workflow and no Dependabot config change. It documents the remainder in the dev guide's Dependabot section: the failure is loud (ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION in make verify), and the targeted fix is to set the bumped package's manifest range to a release that resolves under the policy (committed to the Dependabot branch), run plain pnpm install, then pnpm install --frozen-lockfile to confirm, in place of the full pnpm clean --lockfile regeneration.

I did not build the write-back workflow (issue option 3). It needs a token that can push to dependabot/npm_and_yarn/** branches and still trigger CI (a GITHUB_TOKEN push does not), and no such token exists in the repo's secrets. That is a decision for a maintainer, so #441 stays open for it.

Test plan

Related Issues

Refs #441 (stays open for the write-back workflow). Part of #740.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Wjv2nu841pxTMdUWSAPmDH

Dependabot's cooldown is already set; transitive packages it re-resolves can still trip pnpm's minimumReleaseAge check, which now fails loudly under --frozen-lockfile. Record the targeted remedy in the dev guide and note that the write-back workflow remains open in #441.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Wjv2nu841pxTMdUWSAPmDH
@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: b4e4011c-5151-4e72-aa34-5e627ffc0bfe

📥 Commits

Reviewing files that changed from the base of the PR and between c01b912 and 543d0ba.


📒 Files selected for processing (2)
  • CHANGELOG.md
  • docs/src/content/docs/development.md

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📜 Recent review details
🧰 Additional context used
📚 Code guidelines (2)
AGENTS.md — auto-discovered
docs/src/content/docs/development.md — auto-discovered

📓 Path-based instructions (2)
Source excerpt: **WH001 applies to every tracked Markdown file, with no carve-out** — `AGENTS.md`, `CHANGELOG.md`, `.github/` CI docs and `.claude/` agent prompts included.

📄 CodeRabbit inference engine (AGENTS.md)

Files:

  • docs/src/content/docs/development.md
  • CHANGELOG.md

Source excerpt: Run `make fix` to apply them.

📄 CodeRabbit inference engine (docs/src/content/docs/development.md)

Files:

  • docs/src/content/docs/development.md
  • CHANGELOG.md



🔇 Additional comments (1)
docs/src/content/docs/development.md (1)

611-611: 🎯 Functional Correctness

The concern remains undecidable. The documentation makes specific claims about pnpm 11.21.0 resolving only the affected subtree and preserving unrelated pins, but the supplied evidence contains no execution against a failing lockfile. Static configuration cannot establish those runtime results.





📝 Summary

Summary by CodeRabbit

  • Documentation
    • Updated the development guide with steps for resolving pnpm’s minimum release age check during frozen installs, including updating a package version range and reinstalling.
    • Clarified that regenerating the entire lockfile may introduce unrelated updates and that automated write-back remains unresolved.

Walkthrough

The development guide now explains how to address Dependabot lockfiles rejected by pnpm’s minimumReleaseAge check. The changelog records the guidance.

Changes

Dependabot lockfile guidance

Layer / File(s) Summary
Document lockfile recovery steps
docs/src/content/docs/development.md, CHANGELOG.md
The guide describes the error, targeted manifest range updates, install and verification commands, and limitations of full lockfile regeneration and automation. The changelog summarizes the guidance.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Suggested reviewers: taitelee


Merge Risk: ⚪ Minimal · up to 543d0

The documentation is mergeable after normal checks. Its recovery procedure has not been independently validated against a failing lockfile.

Pre-merge checks | Passed 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Description check Passed The description accurately explains the documentation change, its scope, validation, limitations, and related issues.
Linked Issues check Passed The description references #441 and #740, and the objectives explain how both relate to this documentation change.
Out of Scope Changes check Passed The changes are limited to the development guide and match the stated objective. No unrelated workflow or Dependabot configuration changes were added.
Title check Passed The title clearly and concisely identifies the documentation change for the Dependabot release-age lockfile fix.


✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

✨ Simplify code
  • Commit to this branch
  • Create a new PR


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added documentation Improvements or additions to documentation area/docs Documentation, site/, README labels Oct 9, 2026
@EricAndrechek

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

📚 Docs preview is live → https://92aeeca9-wavehouse-docs.wave-rf.workers.dev

@EricAndrechek

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@EricAndrechek
EricAndrechek marked this pull request as ready for review October 9, 2026 21:39
@EricAndrechek
EricAndrechek requested review from a team and taitelee October 9, 2026 21:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/docs Documentation, site/, README documentation Improvements or additions to documentation

Projects

Status: Backlog

Development

Successfully merging this pull request may close these issues.

1 participant