Repository navigation
docs(deps): document the Dependabot release-age lockfile fix - #801
EricAndrechek wants to merge 1 commit into
Conversation
Dependabot's cooldown is already set; transitive packages it re-resolves can still trip pnpm's minimumReleaseAge check, which now fails loudly under --frozen-lockfile. Record the targeted remedy in the dev guide and note that the write-back workflow remains open in #441. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Wjv2nu841pxTMdUWSAPmDH
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details🧰 Additional context used📚 Code guidelines (2)📓 Path-based instructions (2)Source excerpt: **WH001 applies to every tracked Markdown file, with no carve-out** — `AGENTS.md`, `CHANGELOG.md`, `.github/` CI docs and `.claude/` agent prompts included.📄 CodeRabbit inference engine (AGENTS.md) Files:
Source excerpt: Run `make fix` to apply them.📄 CodeRabbit inference engine (docs/src/content/docs/development.md) Files:
🔇 Additional comments (1)
📝 SummarySummary by CodeRabbit
WalkthroughThe development guide now explains how to address Dependabot lockfiles rejected by pnpm’s ChangesDependabot lockfile guidance
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Other Suggested reviewers: Merge Risk: ⚪ Minimal · up to The documentation is mergeable after normal checks. Its recovery procedure has not been independently validated against a failing lockfile. Pre-merge checks |
|
|
@coderabbitai review |
|
|
📚 Docs preview is live → https://92aeeca9-wavehouse-docs.wave-rf.workers.dev
|
|
@coderabbitai review |
✅ Action performedReview finished.
|
Summary
The code half of #441 has already landed:
.github/dependabot.ymlcarries a 7-daycooldown(with the same@wave-rf/*and@wavehouse/*excludes asminimumReleaseAgeExclude), and pnpm 11.21 now verifies the lockfile againstminimumReleaseAgeeven under--frozen-lockfile, so the "CI does not catch this" premise in the issue is stale. What is left is transitive packages that Dependabot's age-blind resolver pulls in, which acooldowncannot prevent (it gates only the package being bumped).This PR adds no workflow and no Dependabot config change. It documents the remainder in the dev guide's Dependabot section: the failure is loud (
ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATIONinmake verify), and the targeted fix is to set the bumped package's manifest range to a release that resolves under the policy (committed to the Dependabot branch), run plainpnpm install, thenpnpm install --frozen-lockfileto confirm, in place of the fullpnpm clean --lockfileregeneration.I did not build the write-back workflow (issue option 3). It needs a token that can push to
dependabot/npm_and_yarn/**branches and still trigger CI (aGITHUB_TOKENpush does not), and no such token exists in the repo's secrets. That is a decision for a maintainer, so #441 stays open for it.Test plan
npm-deps-7a9629ed98) in a scratch worktree and ranpnpm install --lockfile-only --frozen-lockfileon pnpm 11.21.0. Output:Verifying lockfile against supply-chain policies (1086 entries)thenLockfile passes. This confirms the policy check runs under--frozen-lockfileand that a post-cooldown Dependabot lockfile passes it. Scratch worktree removed afterwards.scripts/lint-pr-title.shaccepts the title.ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATIONbehaviour and the targeted-install remedy rest on the measurements recorded in the fix(deps): Dependabot lockfiles bypass the minimumReleaseAge cooldown #441 comment from 2026-09-09 (PR deps: bump astro from 7.1.6 to 7.2.8 #571).make verifycovers markdown lint for the two changed files; nothing else is exercised by a docs-only change.Related Issues
Refs #441 (stays open for the write-back workflow). Part of #740.
🤖 Generated with Claude Code
https://claude.ai/code/session_01Wjv2nu841pxTMdUWSAPmDH